注册并分享邀请链接,可获得视频播放与邀请奖励。

23pds (山哥) 的个人资料封面
23pds (山哥) 的头像

23pds (山哥) (@im23pds)

@im23pds
Dad/@SlowMist_Team Partner&CISO/#Web3# Security Researcher/RedTeam/Pentester/Ai安全猎人 #bitcoin#
6K 正在关注    15.2K 粉丝
1-Click GitHub Token Stealing via a VSCode Bug
🤣 AI 还说不懂 人心险恶
大裁员后的翻车来了。这几天,Meta 旗下的 Instagram,被曝 AI 助手出现史诗级漏洞,导致多个 Ins 博主账号被盗。 平台给 AI 助手,默认开了一个超级权限,可以在无任何验证的情况下,直接帮人修改 Ins 的绑定邮箱。 流程则是 1. 用 VPN 假装自己在目标账号的国家 2. 跑到 Meta AI 聊天里,说我是这个账号的主人,想换个新邮箱 3. AI 傻乎乎地相信了,发验证码给黑客的新邮箱 4. 黑客把验证码告诉 AI,AI 就直接把账号邮箱,换成黑客的了,然后黑客就能重置密码、抢走账号 目前,Meta 已紧急修补了这个巨大漏洞。
显示更多
“misunderstanding" lies. just a good phrase to avoid responsibility 😂 it would be nice to provide some better changes in rules to clear SLAs, pay some respects to researchers and stop doing PRs like this complete gaslighting lmao
显示更多
Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community, and will continue to take your feedback seriously. To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate. We recognize the work that goes into researching and submitting a vulnerability. We are committed to approaching every interaction with transparency, clear communication, and professionalism. We continue to believe strongly in Coordinated Vulnerability Disclosure as the foundation for protecting customers and improving our products. Each year we process a high volume of vulnerability reports. That volume continues to grow and will continue with the rise of AI-enabled research. We acknowledge that some interactions have fallen short and are working to learn from them. Many of us have experience on both sides of this work, as researchers reporting vulnerabilities and as responders triaging and assessing them. That perspective informs how we approach this feedback and the importance we place on getting it right, particularly as the volume and complexity of research continues to grow. The security community plays a vital role in helping us protect customers. We are committed to maintaining a constructive and respectful relationship and growing together. We know that, given the nature of this work, there will at times be misunderstandings. We remain committed to engaging in good faith and to providing a respectful and professional experience for all researchers, regardless of past interactions.
显示更多
🚨
Exploit Alert 🚨 Fluid (@0xfluid) was drained of about $215K on Ethereum. Not a contract bug. Fluid pays out rewards from a Merkle list that one key proposes and a second key approves. An attacker held both of those operational keys, pushed a reward list that paid only themselves, approved it, and claimed with an empty proof. The two-person control meant nothing once one person held both keys. Taken from three reward distributors: 112,883 $FLUID, 47,903 $GHO, and a little $cbBTC. The tokens were swapped to ether and routed into Tornado Cash. Fluid's lending markets, vaults, DEX, and user deposits were never touched. The team removed the compromised keys and swept the remaining reward funds to safety within about ten hours. Public comms said only that claiming is paused for updates, with no mention of a key compromise or a loss. Full forensics:
显示更多
⚠️
🚨 NPM Malware-slop Alert!🚨 We detected and reported a malware-slop package to npm - the malware uses it's OWN PRIVATE GitHub token, which is EMBEDDED INSIDE the malware itself - to read sensitive information and upload it to the threat actor's GitHub repository. The malware is still live on npm - The threat actor's GitHub page was opened 5h ago - Detailed report will be published tomorrow.
显示更多
4-Vulnerability Exploit Chain in DataEase My team found a 4-vulnerability exploit chain allowing unauthenticated RCE on DataEase. Combined with a previously published vulnerability (CVE-2026-23958) - these new vulns complete the attack chain, bypassing JDBC, SQL Injection and a Quartz scheduler injection that runs periodically and executes a crafted payload on the machine. We have also a video showing the exploit POC in action :) Read the full blog:
显示更多
注意~ thanks @SocketSecurity 🫵
🚨 SlowMist TI Alert 🚨 MistEye has detected a cross-registry supply chain attack targeting developers through malicious packages published to npm, PyPI, and The campaign includes 34+ malicious packages and 384+ related versions. Targeted communities include crypto, DeFi, Solana, Sui/Move, and AI developers. Potential attacker actions include theft of crypto wallets, SSH keys, cloud credentials, GitHub/AWS tokens, browser data, environment variables, and developer secrets. Some payloads also attempt persistence through .cursorrules, CLAUDE.md, Git hooks, shell hooks, cron, systemd, and SSH. Remove affected packages immediately. Isolate impacted systems, preserve logs, rotate exposed credentials, rebuild CI runners and developer machines from clean images, and review GitHub, cloud, SSH, and wallet activity. As always, stay vigilant!
显示更多
🚨SlowMist TI Alert🚨 💸 Loss: 8,080.16 USDT + 11,702.08 USDC 🔍 Root Cause: `WUSD._deglove()` uses `GLOVE.creditlessOf(msg.sender)` as the unlock base without verifying the source or epoch of creditless GLOVE. In addition, WUSD’s epoch/vesting logic was driven by cumulative wrap volume, which could be flash-loan amplified and advanced 100+ epochs inside one tx. This converted creditless GLOVE into transferable GLOVE atomically. 📌 Attacker: 0x88329a09428778f62bc0c8baac0997864e5a57f8 📌 Victim: Uniswap V3 liquidity pools (GLO/USDT: 0xa2bd1a142ff49131b8cc70a332bda0125018c324, GLO/USDC: 0xb89f65d6c7d33a35da7c01934e310a6f40e18a1f) 📌 Vulnerable Contract: WUSD (0x068e3563b1c19590f822c0e13445c4fa1b9eefa5) Attacker exploited a credit accounting flaw in WUSD/GLOVE to mint and unlock transferable GLOVE, then drained USDT/USDC from Uniswap V3 pools. Powered by #SlowMist#.AI
显示更多
🎉 正式宣布!imBack 已成为 @SlowMist_Team 慢雾区生态合作伙伴! 慢雾( imBack( 感谢慢雾安全团队的认可与支持! #SlowMist# #区块链安全# #CryptoRecovery# #imBack#
显示更多
🧐 我们@SlowMist_Team 刚刚分析网络犯罪论坛的爆料,黑客可能用Anthropic 的Mythos 安全AI,用它精准突破 GitHub 的防线,偷走约4000个核心内部仓库: 里面有Copilot的源码、CodeQL的算法、Actions运行时和整个计费系统等等太多信息了。 后续分析这些代码,可能会再次攻击,对整个开源社区产生深远安全影响。 cc @evilcos
显示更多
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
显示更多
0
10
73
9
转发到社区
F..k
Monad eBTC/Curvance trace: not a Curvance lending bug. The eBTC admin granted DEFAULT_ADMIN_ROLE to 0x6A0109, who revoked admin, self-granted MINTER_ROLE, minted 1,000 eBTC, posted 45 eBTC as collateral, and borrowed ~11.296 WBTC. Looks like admin-key/role compromise. Key txs: admin grant 0x1684...cf6f, mint 0x2cc9...57c0, borrow 0xa797...778e.
显示更多
RIP for all 6 entries. The last-minute patch turned out quite solid. So I decided to give my exploit a proper goodbye. Enjoy!
6 Firefox entries at pwn2own. 5 withdrawals due to our 150.0.3 security release. 1 failed attempt. 0 Exploits. No incidents. Time to party :)
0
8
374
51
转发到社区
🚨
🚨 SlowMist TI Alert 🚨 MistEye has received critical threat intelligence regarding an active supply chain attack compromising node-ipc, a foundational Node.js library. The malicious releases have been identified as versions 9.1.6, 9.2.3, and 12.0.1. Threat actors injected an obfuscated credential-stealing payload into the CommonJS bundle. Once loaded, it silently harvests over 90 categories of developer data—including AWS, Azure, GCP, SSH, K8s tokens, and Terraform states—and exfiltrates it to attacker-controlled infrastructure. We have synchronized this IOC with our clients immediately. Detection & Remediation: Please urgently audit your environments for exposure: • Dependencies: Run npm ls node-ipc --all to identify direct or transitive inclusions. • Lockfiles: Search package-lock.json, yarn.lock, or pnpm-lock.yaml for the affected version ranges. • CI/CD: Review pipeline jobs executed after May 14, 2026, that may have pulled loose semver updates (~9.1.x, ^12, etc.). ⚠️ Critical Action: If a compromised version was installed, assume certain compromise. Do not wait for exfiltration confirmation. Downgrade to a known safe version immediately and aggressively rotate all credentials, tokens, and environment secrets present on the affected machine or CI runner. As always, stay vigilant!
显示更多
已经拿到一些在野攻击样本了,目前可以肯定的这是针对旧版 iOS 的 iPhone,Safari 浏览器,有加密货币钱包的用户群体。 有假冒色情直播、波场能量站、退款流程、漏洞预警等等的网页,如果旧版本 iPhone 用户的 Safari 浏览器打开了这种网页,没有关闭的情况下,此时解锁钱包 App 准备使用,明文私钥就可能会被这种网页里的恶意 JavaScript 利用代码给盗走。 系统更新要重视,尤其看到有安全漏洞修复有关的更新。否则你的那些钱包怎么被盗的你都知道。 细节我们会看情况再决定披露。
显示更多
🚨 node-ipc 再次遭受入侵 今天发布的 node-ipc 三个恶意版本(9.1.6、9.2.3、12.0.1),它们携带相同的凭证窃取负载。 该包每周下载量超过 1000 万。
🚨 BREAKING: node-ipc compromised. Again. Three malicious versions of node-ipc (9.1.6, 9.2.3, 12.0.1) were published today carrying an identical credential-stealing payload. This package has 10M+ weekly downloads. Here's what happened: An attacker injected an 80KB obfuscated IIFE into the CommonJS bundle. It fires on every require('node-ipc') call. No special config needed, just importing the package is enough. What it steals: → AWS, Azure, GCP credentials → SSH private keys → Kubernetes configs → Docker tokens → GitHub CLI tokens → AI tool configs (including Claude) → Terraform state → 90+ credential file patterns in total Everything gets gzipped and exfiltrated to an attacker-controlled domain (sh[.]azurestaticprovider[.]net) via DNS TXT queries and HTTPS POST, designed to look like normal traffic. The attacker published across two major version lines simultaneously (9.x and 12.x) to maximize blast radius. Semver ranges like ^9, ~9.1.x, ~9.2.x, ^12, and ~12.0 all resolve to compromised versions automatically on the next install or lockfile refresh. Key details: Only the CommonJS bundle (node-ipc.cjs) is affected. ESM imports are clean. The 9.x releases are fabricated. The 9.x line never shipped a .cjs bundle before this attack. This is a different actor from the 2022 peacenotwar incident. Purely financial, credential-theft motivation. If you installed any of these versions, assume all secrets on that machine are compromised. Rotate everything. Our full technical breakdown covers the attack chain stage by stage, IOCs, and how to check if you're affected:
显示更多
凌晨刷到这条,我脊背瞬间发凉,全身鸡皮疙瘩都起来了。 @zcbenz,MLX维护者、Electron.js创始人,在Apple亲手把这个消息放了出来: MLX的CUDA后端,所有测试全部通过! 那个曾经被当成“苹果硅独占玩具”的MLX,现在直接杀进了NVIDIA的主场。 同一套代码。 Mac上极致丝滑,NVIDIA显卡上也全速狂飙。 以前大家还在PyTorch的兼容地狱里挣扎,Apple用MLX悄无声息打出一记王炸。 本地AI的跨平台时代,真的要来了。 而且来得比所有人想象的都要猛、都要狠。 我现在只剩下一个感觉——血脉喷张。 MLX的CUDA时代,正式拉开序幕。 你敢信!
显示更多
We have achieved a milestone in MLX that all tests are passing in CUDA backend now.
0
22
320
55
转发到社区
AI 加持下 Linux 和 Nginx 被打成了马蜂窝🤣
wtf 😂
NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at
显示更多
wtf.. 又一个…😅
#Fragnesia# 🚨: a new #Linux# kernel LPE in the Dirty Frag family lets unprivileged attackers gain root via ESP-in-TCP page-cache corruption. No host-level privileges required. Patch ASAP, disable esp4/esp6/rxrpc if unused, and restrict user namespaces.
显示更多
MistEye 🚨 NPM 蠕虫 Shai-Hulud 开源,供应链风险升高。 Shai-Hulud 是近期备受关注的 'Git 恶意蠕虫',现已被开源。 这意味着 TeamPCP 或其他方发布了完整可执行版本,潜在威胁显著增加。 各项目方和平台需提高警惕,立即加强防护,防范 NPM 供应链攻击。
显示更多