Tag: Security

Fake software on GitHub and SourceForge distribute Deno RAT 

The post Fake software on GitHub and SourceForge distribute Deno RAT⤴︎  appeared first on Malwarebytes⤴︎.

Nikhil Das Nikhil Das

I found 900 S3 buckets exposing Terraform state files. 41 had live AWS credentials.

I built a scanner that guesses S3 bucket names and looks for .tfstate files.

Piyush Gupta Piyush Gupta

I poisoned a Hugging Face dataset and it stayed up for 6 months.

I uploaded a "fine-tuning dataset" to Hugging Face with 1,000 rows of

Piyush Gupta Piyush Gupta

I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty.

I was poking at a fintech’s mobile API and noticed something that

Piyush Gupta Piyush Gupta