Rami

@ramimac.me

security, for the internet, at Wiz opinionated about security. knowledge hubs at rami.wiki, thoughts at ramimac.me

There is currently a wave of supply chain attacks clustered around TeamPCP, a financially motivated threat actor. Today, the latest news was telnyx's python package had malicious versions pushed. This follows trivy, checkmarx (kics), and litellm incidents. Get the details: ramimac.me/teampcp

TeamPCP Supply Chain Campaign | Attack Timeline & IOCs

Timeline and IOCs for TeamPCP's March 2026 supply chain campaign. Trivy, KICS, LiteLLM, and 45+ npm packages compromised through chained credential theft.

ramimac.me

> We've set up a web endpoint so vetted ... security researchers can submit suspected exposed credentials for review > To report exposed Google Cloud credentials, please contact gcp-credentials-reports@google.com cloud.google.com/blog/product... really buried the lede!

Securing open-source credentials at scale | Google Cloud Blog

We’ve developed a powerful tool to scan open-source package and image files by default for leaked Google Cloud credentials. Here’s how to use it.

cloud.google.com

In light of recent GitHub Actions incidents (Ultralytics, tj-actions...), I wrote up a practical guide to hardening for @wizsecurity.bsky.social Covers permissions, secrets, 3rd-party Actions, ++ Use it to avoid learning these lessons the hard way: www.wiz.io/blog/github-...

Hardening GitHub Actions: Lessons from Recent Attacks | Wiz Blog

Build resilient GitHub Actions workflows with insights from real attacks, missteps to avoid, and security tips GitHub’s docs don’t fully cover.

wiz.io

Keep an eye out for notices - AWS RDS Protection for Guardduty seems to have had some issues collecting logs. Unclear how pervasive this was!

Bild

I've spent dozens of hours reading State of Cloud Security reports You know, the ones that use data from their CSPM product And I've realized the findings substantially reflect how well that tool helps customers secure their clouds I wrote up some examples, both good and bad (🔗 in 🧵)

Bild

I (finally) wrote up my thoughts on "Founder Mode" and the Brian Chesky morality tale about how he turned around Airbnb company culture. This has made it into the Silicon Valley water table; it must be dealt with. There are some good nuggets within; let's dig them out. charity.wtf/2024/12/17/f...

“Founder Mode” and the Art of Mythmaking

I’ve never been good at “hot takes”. Anyone who knows anything about marketing can tell you that the best time to share your opinion about something is when everyone is all worked up about it. Hot …

charity.wtf

New Threat Vector Unlocked 1. Find the Crunchbase page of a cybersecurity company that just raised VC funding 2. Change the page details (which anyone with a Crunchbase account can do) to a personal CashApp page 3. ???? 4. Profit! (?)

Bild

Speed reading @skamille.bsky.social & Ian Nowland's new book: Platform Engineering Interesting tidbits in 🧵 paved roads 🛣️: “layers multiple offerings together into easy-to-use workflows” vs railways 🚟 building to fill a "meaningful gap that is not covered by any existing product”

Cover image for the book "Platform Engineering", from O'Reilly, with a green gecko(?)