Mike

@theomegabit.xyz

AWS Pro | Cloud | Security @trek10.com | Tech enthusiast Musically trapped between a metallic headbang and a bass wobble | Photographer (bsky): @betapixels.photography

I think I’m in the market for another mechanical keyboard. ~75% size. Butter keys. Backlit if possible. I currently have the Nuphy Air75 v1. What should I look at now?

Yep, I've been pwned. 2FA reset email, looked very legitimate. Only NPM affected. I've sent an email off to @npmjs.bsky.social to see if I can get access again. Sorry everyone, I should have paid more attention. Not like me; have had a stressful week. Will work to get this cleaned up.

@charlieeriksen.bsky.social · 11mo ago

@bad-at-computer.bsky.social Hey. Your npm account seems to have been compromised. 1 hour ago it started posting packages with backdoors to all your popular packages.

Amazon Q shipped a feature where a rando hacker told it to run aws iam delete-user, and AWS said “Sure thing, pal!” They caught it only because a journalist asked. This isn’t “move fast and break things," it's “move fast and let strangers write your roadmap.” www.lastweekinaws.com/blog/amazon-...

Amazon Q: Now with Helpful AI-Powered Self-Destruct Capabilities - Last Week in AWS Blog

Today 404Media released a truly stunning report that almost beggars belief. To break it down into its simplest form: A hacker submitted a PR. It got merged. It told Amazon Q to nuke your computer and ...

lastweekinaws.com

There’s a decent amount of talk and research on specific AWS api calls that aren’t logged to cloudtrail but is there an all encompassing list (GitHub hopefully) that covers everything currently known? #awssecurity