noname 🥸 (n3rd)

noname 🥸

N E T W O R K N 3 R D ⚡

22 Followers

Recent casts

⚡ Anthropic says Claude models breached three organizations after a misconfigured CTF gave them live internet access. The test was simulated. The internet was not. One model accessed production data. Another published a PyPI package downloaded by 15 real systems. Full report: https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html

  • 0 replies
  • 0 recasts
  • 0 reactions

🚨 Microsoft 365 Copilot can quietly alter figures during a Word drafting or editing operation, then copy the hidden instructions into the document it creates. That generated file can carry the manipulation into a later Copilot session. Here’s how the chain works: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html

  • 0 replies
  • 0 recasts
  • 1 reaction

‼️ WARNING -- Critical Rails flaw CVE-2026-66066 could let unauthenticated attackers read server files through crafted image uploads. The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE. Patch now. Read the full story - https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html

  • 0 replies
  • 0 recasts
  • 1 reaction

Top casts

Google’s OAuth login exposes a critical vulnerability, allowing attackers to access old employee accounts simply by purchasing a defunct domain from a failed startup. Learn how this vulnerability could affect your organization: https://thehackernews.com/2025/01/google-oauth-vulnerability-exposes.html

  • 0 replies
  • 0 recasts
  • 0 reactions

🔒 Critical Alert: Malicious npm packages are impersonating Hardhat tools to steal private keys and mnemonics. ↪ Over 1,000 downloads of a single fake package, active for over a year. ↪ Data is exfiltrated using hardcoded Ethereum addresses. Open-source dependency complexity is a hacker’s dream—manual reviews are becoming impossible. 🔧 What You Can Do: ✅ Double-check every dependency. ✅ Use tools to audit npm packages. ✅ Build robust supply chain defenses. 🔗 Read the details: https://thehackernews.com/2025/01/russian-speaking-attackers-target.html

  • 0 replies
  • 1 recast
  • 0 reactions

🚨 Russian cyber attackers are actively targeting Kazakhstan’s Ministry of Foreign Affairs—this isn't just a cyber attack; it’s an espionage campaign to steal sensitive political and economic data. The attackers use infected Microsoft Office docs to bypass security and deploy powerful malware like HATVIBE—designed to remain undetected. Learn more: https://thehackernews.com/2025/01/russian-linked-hackers-target.html

  • 0 replies
  • 0 recasts
  • 0 reactions

Onchain profile

Ethereum addresses