netbroom

@netbroom.bsky.social

Founder of @pulsedive.com. Creator of threatfeeds.io.

Check us out on Oct. 23rd for a group talk on cybersecurity topics! Everything ranging from current events, different security realms or just ranting about the state of cybersecurity today! Link in bio for more details!

BildBildBildBild

details on NPM supply chain compromise: - targets crypto - client-side (executes in browser) - pushed to repos sept 8 - NPM account compromised through phishing email with domain npmjs[.]help www.aikido.dev/blog/npm-deb...

npm debug and chalk packages compromised

The popular packages debug and chalk on npm have been compromised with malicious code

aikido.dev

Josh Junon@bad-at-computer.bsky.social · 11mo ago

Yep, I've been pwned. 2FA reset email, looked very legitimate. Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again. Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.

Browser extensions are commonly used, but present a significant security risk as a growing threat vector. Our newest blog looks at examples from January 2025, including Cyberhaven and GraphQL Network Inspector, to discuss how threat actors compromise extensions. blog.pulsedive.com/compromised-...

Compromised Browser Extensions - Jan 2025 | Pulsedive Blog

Learn how threat actors leverage browser extensions as an attack vector, including examples for Cyberhaven and GraphQL Network Inspector.

blog.pulsedive.com

absolutely wild searching for a laptop today. each major manufacturer has 5-10 lines of laptops, each line has 5-10 models with different keyboards and port configs, and each model has 5-10 configurations with different processors and options. i just want 14' w/ dedicated Home/End keys...

if you want to encrypt + compress files, always compress first. encryption introduces entropy making compression less effective. some file formats like JPEG are already compressed, so additional compression won't have much of an impact.