thepwnicorn

69 Followers
71 Following
718 Posts
Working in AppSec by day, posting on here by night. he/him
Bitwarden CLI has been compromised in a supply chain attack that targeted KICS. #bitwarden #kics #malware #supplychain https://socket.dev/blog/bitwarden-cli-compromised
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.

Socket
You can't hack me I'm out of scope
Imagine being a coder but thinking there's no artistry to writing code. What an empty existence

I just posted a blog, it is 100% nicer and more restrained than our development team would have posted. Read between the lines, people.... ;-)

https://www.isc.org/blogs/2026-04-16-How-to-report-a-vulnerability/

How to report a security vulnerability, 101

At ISC, we sincerely value the contributions of our users, and security researchers, who analyze and probe our software for vulnerabilities.

@GossiTheDog A bit scary how quickly they regurgitate talking points.

Well this is truly bad. US national level OS-level age verification bill. https://www.congress.gov/bill/119th-congress/house-bill/8250/all-info

The text of it isn't out yet.

EDIT: Well the text is now out and it's as bad as you could imagine. It's not even just that you need to verify your age to access a website... operating systems must verify your age to let you *use a computer at all*

EDIT EDIT: Thanks to @Andres4NY for pointing out that it also holds responsible anyone who has any software shipped on the operating system of a computer, meaning FOSS developers eveywhere

From the same author as BlueHammer we now have RedSun.

This works ~100% reliably to go from unprivileged user to SYSTEM against Windows 11 and Windows Server 2019+ with April 2026 updates, as well as Windows 10, as long as you have Windows Defender enabled. Any system that has cldapi.dll should be affected.

@hacks4pancakes it's looking really good! I like the premise of an insider threat, the false trail of information, different approaches one can take, and various ways intrusion may get detected. It seems to be well-suited for good story telling and mechanics that drive the story forward. Haven't had the chance to run it yet, but shared it with fellow friends who are into TTRPGs.