🚀 Security - Typosquatting Packages on PyPI
PyPI typosquatting packages targeting widely used Python packages have been discovered. These packages can compromise systems if not caught. The attack timeline is as follows: a new PyPI account was registered three hours ago, and one hour later, four packages were published.
Key Points:
• Typosquatting packages on PyPI target widely used Python packages.
• Attack timeline: new PyPI account registered three hours ago, four packages published one hour later.
• Packages published: 0requests, py-0requests, py-requests, requests.
🔗 Resources:
• Original post ↗ - Original post
• Anyrun App ↗ - Security research and analysis
• Anyrun App ↗ - Security research and analysis
• Anyrun App ↗ - Security research and analysis
🚨 Security - Infostealers Circulate at High Volume
Infostealers are circulating at high volume across US organizations and can feed into ransomware intrusions. Law enforcement disruptions don't shrink demand. When Lumma Stealer was disrupted in 2025, Remus Stealer emerged as a direct technical successor within weeks.
Key Points:
• Infostealers circulate at high volume across US organizations.
• Infostealers can feed into ransomware intrusions.
• Law enforcement disruptions don't shrink demand.
🔗 Resources:
• Original post ↗ - Original post
• Anyrun App ↗ - Security research and analysis
• Anyrun App ↗ - Security research and analysis
• Anyrun App ↗ - Security research and analysis
🚨 Security - Secure Boot Bypass on NVIDIA Jetson
Secure Boot Bypass on NVIDIA Jetson has been discovered. It's time to patch and fuse those keys.
Key Points:
• Secure Boot Bypass on NVIDIA Jetson has been discovered.
• Patch and fuse keys to secure system.
🔗 Resources:
• Original post ↗ - Original post
• Bl4sty ↗ - Security research and analysis
• Qkaiser ↗ - Security research and analysis
• Qkaiser ↗ - Security research and analysis
🚨 Security - CVE-2025-31200 and CVE-2025-31201
CVE-2025-31200 and CVE-2025-31201 were attributed to NSO Group. Most recent zero-click chain that appears to be attributable to them.
Key Points:
• CVE-2025-31200 and CVE-2025-31201 attributed to NSO Group.
• Zero-click chain appears to be attributable to NSO Group.
🔗 Resources:
• Original post ↗ - Original post
• HackingLZ ↗ - Security research and analysis
• Billmarczak ↗ - Security research and analysis
• Billmarczak ↗ - Security research and analysis
🚨 Security - Warpgate v0.28.0-beta.1
Warpgate v0.28.0-beta.1 is a fully transparent SSH, HTTPS, Kubernetes, MySQL, and Postgres bastion/PAM that doesn't need additional client-side software.
Key Points:
• Warpgate v0.28.0-beta.1 is a fully transparent SSH, HTTPS, Kubernetes, MySQL, and Postgres bastion/PAM.
• No additional client-side software required.
🔗 Resources:
• Original post ↗ - Original post
• KitPloit ↗ - Security research and analysis
• KitPloit ↗ - Security research and analysis
• KitPloit ↗ - Security research and analysis
🚨 Security - Knight Office Phishing Kit
Knight Office phishing kit was discovered in August. Get the details.
Key Points:
• Knight Office phishing kit discovered in August.
• Details available.
🔗 Resources:
• Original post ↗ - Original post
• HuntressLabs ↗ - Security research and analysis
• HuntressLabs ↗ - Security research and analysis
• HuntressLabs ↗ - Security research and analysis
🚨 Security - Stop Paying Monthly: 1TB of Koofr Cloud Storage
Stop paying monthly: 1TB of Koofr cloud storage is $129.97 for life.
Key Points:
• 1TB of Koofr cloud storage available for $129.97 for life.
• No monthly payments required.
🔗 Resources:
• Original post ↗ - Original post
• BleepinComputer ↗ - Security research and analysis
• BleepinComputer ↗ - Security research and analysis
• BleepinComputer ↗ - Security research and analysis
🚨 Security - Aussie Engineer Son's US Success Story
Aussie engineer son's US success story could have been an Aust'n success story but for the nuclear BAN. The CEO and Co-Founder, Bobby Gallagher, is an ex-Military Engineer for the Australian Army.
Key Points:
• Aussie engineer son's US success story.
• CEO and Co-Founder, Bobby Gallagher, is an ex-Military Engineer for the Australian Army.
🔗 Resources:
• Original post ↗ - Original post
• Carmel Hilder ↗ - Security research and analysis
• Carmel Hilder ↗ - Security research and analysis
• Carmel Hilder ↗ - Security research and analysis
🚨 Security - Cryptoscope's Continuous Analysis
Cryptoscope's continuous analysis indicates 40% bull-trap risk according to Cryptoscope's continuous analysis at the moment.
Key Points:
• 40% bull-trap risk according to Cryptoscope's continuous analysis.
• Check out Cryptoscope's continuous analysis.
🔗 Resources:
• Original post ↗ - Original post
• OwariDa ↗ - Security research and analysis
• OwariDa ↗ - Security research and analysis
• OwariDa ↗ - Security research and analysis
🚨 Security - Building a Comprehensive Dataset
Building a comprehensive/correct dataset is the most important challenge. Introduce a lot of levers, autoresearch it.
Key Points:
• Building a comprehensive/correct dataset is the most important challenge.
• Introduce a lot of levers, autoresearch it.
🔗 Resources:
• Original post ↗ - Original post
• Bl4sty ↗ - Security research and analysis
• Bl4sty ↗ - Security research and analysis
• Bl4sty ↗ - Security research and analysis