AccessDenied403's Avatar

AccessDenied403

@ad403.bsky.social

Share my learning journey in the field of Blockchain, Crypto and Web3. Security Engineer at taurushq.com See my blog https://rya-sge.github.io/access-denied

44 Followers  |  141 Following  |  22 Posts  |  Joined: 02.03.2025  |  1.6558

Latest posts by ad403.bsky.social on Bluesky


Preview
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link A high-severity OpenClaw flaw allows one-click remote code execution via token theft and WebSocket hijacking; patched in v2026.1.29.

"The problem is that clicking on the link to that web page is enough to trigger a cross-site WebSocket hijacking attack because OpenClaw's server doesn't validate the WebSocket origin header."
thehackernews.com/2026/02/open...

06.02.2026 08:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
How We Exploited Qodo: From a PR Comment to RCE and an AWS Admin Key - Leaked Twice - Kudelski Security Research Center Jan 15, 2026 - Nils Amiet -

Prompt injection and RCE in Qodo Merge, an open-source AI code review tool. Great write-up!
kudelskisecurity.com/research/qod...

03.02.2026 14:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Notepad++ Hijacked by State-Sponsored Hackers | Notepad++

"The attack involved infrastructure-level compromise that allowed malicious actors to intercept and redirect update traffic destined for notepad-plus-plus.org. The incident began from June 2025 until December"
Recommend version: v8.9.1
notepad-plus-plus.org/news/hijacke...

02.02.2026 16:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers North Korean group Konni uses AI-assisted PowerShell malware and phishing via Google ads and Discord to breach blockchain development environments.

"The North Korean threat actor known as Konni has been observed using PowerShell malware generated using artificial intelligence (AI) tools to target developers and engineering teams in the blockchain sector."
thehackernews.com/2026/01/konn...

26.01.2026 09:58 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Gemini AI assistant tricked into leaking Google Calendar data Using only natural language instructions, researchers were able to bypass Google Gemini's defenses against malicious prompt injectionΒ and create misleading events to leak private Calendar data.

Using only natural language instructions, researchers were able to bypass Google Gemini's defenses against malicious prompt injectionΒ and create misleading events to leak private Calendar data.

20.01.2026 12:50 β€” πŸ‘ 12    πŸ” 4    πŸ’¬ 1    πŸ“Œ 0
Preview
ERC-1643: Document Management Standard (ERC-1400) This ERC allows documents to be associated with a smart contract and a standard interface for querying / modifying these contracts, as well as receiving updates (via events) to changes on these docume...

ERC-1643, part of ERC-1400, is one of the oldest tokenization related standard on Ethereum (2018) developed by PolymathNetwork.
It allows to manage on-chain document which is very useful for tokenization and RWA. More information on the Ethereum magician forum: ethereum-magicians.org/t/erc-1643-d...

20.01.2026 19:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - CMTA/CMTAT: Reference Solidity implementation of the CMTAT security token framework developed by CMTA to tokenize financial instruments. Reference Solidity implementation of the CMTAT security token framework developed by CMTA to tokenize financial instruments. - CMTA/CMTAT

The latest release of CMTAT Solidity (v3.1.0), a security token framework for on-chain RWA, includes now Chainlink CCIP support for seamless cross-chain transfers. Available on GitHub

19.12.2025 13:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - CMTA/CMTAT-Solana: Solana version of CMTAT Solana version of CMTAT. Contribute to CMTA/CMTAT-Solana development by creating an account on GitHub.

How do you tokenize RWAs on Solana?
CMTA just released a new specification leveraging the Token Extensions Program (Token-2022).
Now available on GitHub: github.com/CMTA/CMTAT-S...
Glad to have contributed through my work at Taurus

09.12.2025 16:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Shai Hulud Strikes Again (v2) - Socket Another wave of Shai-Hulud campaign has hit npm with more than 500 packages and 700+ versions affected.

Tracking the latest NPM supply-chain attack (β€œShai Hulud”):
β€’ Socket: socket.dev/blog/shai-hu...
β€’ Aikido: www.aikido.dev/blog/shai-hu...

26.11.2025 12:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Bitcoin Core audit - Quarkslab's blog The Open Source Technology Improvement Fund, Inc. mandated Quarkslab to perform the first public security audit of Bitcoin core, the reference open-source implementation of the Bitcoin decentralized p...

Quarkslab engineers Robin David, Mihail Kirov and Kaname just completed the first public security audit of Bitcoin Core, led by
@ostifofficial.bsky.social and funded by Brink.dev

Details on the blog post:
blog.quarkslab.com/bitcoin-core...
Congrats to developers for such software masterpiece !

19.11.2025 15:40 β€” πŸ‘ 6    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Lecture 1. Introduction (Hash-Based Signatures)
YouTube video by Cryptography 101 Lecture 1. Introduction (Hash-Based Signatures)

Great YouTube playlist to learn more about Hash-Based quantum-safe signature schemes (LMS, XMSS and
SPHINCS+). www.youtube.com/watch?v=pt5W...
#cryptography

18.11.2025 16:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Bluesky seems to work, unlike X/Twitter x)

18.11.2025 13:27 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Coinbase Security Series: Open Source MPC Key Management
YouTube video by Base Coinbase Security Series: Open Source MPC Key Management

Coinbase Security series: what is MPC and how to use it for Key Management: youtu.be/qdhM3syDkxM
#cryptography

12.11.2025 06:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
WireTap: Breaking Server SGX via DRAM Bus Interposition Breaking Server SGX via DRAM Bus Interposition

Breaking server SGX via DRAM bus: wiretap.fail

01.10.2025 10:47 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

See also www.aikido.dev/blog/npm-deb... and www.securityalliance.org/news/2025-09...

09.09.2025 06:09 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

"The malware did more than just steal SSH keys, npm tokens, and .gitconfig files - it weaponized AI CLI tools (including Claude, Gemini) to aid in reconnaissance and data" www.stepsecurity.io/blog/supply-...

28.08.2025 18:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Stav Beno (starkware) - From Design to Benchmarking: BLAKE Hash AIR for the Stwo Prover
YouTube video by [EthCC] Livestream 6 Stav Beno (starkware) - From Design to Benchmarking: BLAKE Hash AIR for the Stwo Prover

Algebraic intermediate Representation (AIR) for Blake Hash youtu.be/INtBA-9vJpU?... hackmd.io/@starkware-h...

13.07.2025 12:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Yehuda Lindell (Coinbase)_Coinbase's cb-mpc Open-Source Library YouTube video by [EthCC] Livestream 4

Coinbase MPC wallet library presentation at EthCC m.youtube.com/live/ppeyz_J...

01.07.2025 19:43 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Taurus Blog - Conditional Transfers with CMTAT & Taurus-CAPITAL: A Step-by-Step Guide Conditional Transfers with CMTAT & Taurus-CAPITAL: A Step-by-Step Guide

My last article about ERC-20 ConditionalTransfer is available on Taurus blog: www.taurushq.com/blog/tokeniz...
Based on CMTAT, an open-source project: github.com/CMTA/CMTAT
#solidity

29.06.2025 11:09 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Coinbase fixes 2FA log error making people think they were hacked Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.

Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.

27.04.2025 14:21 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
MITRE warns that funding for critical CVE program expires today MITRE Vice President Yosry Barsoum has warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) programs expires today, which could leadΒ to widespread disruption acrossΒ the global cybersecurity industry.

MITRE Vice President Yosry Barsoum has warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) programs expires today, which could leadΒ to widespread disruption acrossΒ the global cybersecurity industry.

16.04.2025 02:16 β€” πŸ‘ 12    πŸ” 9    πŸ’¬ 0    πŸ“Œ 1
Preview
Ethereum NFT Standards: ERC-721, ERC-1155, ERC-6551, and More Non-Fungible Tokens (NFTs) enable unique, verifiable ownership of digital and real-world items on the blockchain. While ERC-721 remains the main standard to represent NFTs on Ethereum and EVM blockcha...

NFTs are used to represent unique items on the blockchain. As you may know, the most known standard on Ethereum is ERC-721. Since its creation, several other standards (ERC-1155, ERC-2981, ERC-4907,...) have emerged to meet various use cases. More details here: rya-sge.github.io/access-denie...

02.04.2025 05:58 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Why Secure Elements make a crucial difference to Hardware Wallet Security | Ledger In contrast with the previous generations of Trezor devices, which the Ledger Donjon showed to be vulnerable to physical seed recovery attacks, the Trezor Safe line of products brings huge security im...

Ledger's article on the security and integrity of the Trezor Safe 3 crypto wallet firmware is a great read to better understand how the new Trezor models (Safe Family) work (Secure Element, firmware integrity, chips used)
www.ledger.com/why-secure-e...
blog.trezor.io/trezors-mult...

27.03.2025 10:55 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Taurus Blog - ERC-1400 for Tokenized Securities: Analysis and Deployment with Taurus-CAPITAL ERC-1400 for Tokenized Securities: Analysis and Deployment with Taurus-CAPITAL

How to tokenize on Ethereum and EVM based blockchain? My last article on Taurus blog is a deep dive into ERC-1400, one of the oldest tokenization standards (2018). www.taurushq.com/blog/erc-140...

25.03.2025 11:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub Action hack likely led to another in cascading supply chain attack A cascading supply chain attack that began with the compromise of the "reviewdog/action-setup@v1" GitHub Action is believed to have led to the recent breach of "tj-actions/changed-files" that leaked CI/CD secrets.

A cascading supply chain attack that began with the compromise of the "reviewdog/action-setup@v1" GitHub Action is believed to have led to the recent breach of "tj-actions/changed-files" that leaked CI/CD secrets.

18.03.2025 16:04 β€” πŸ‘ 3    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0

A couple weeks ago we published our monthly release of ZK Mesh: the February 2025 Recap.

Wondering which articles/threads are the most popular amongst our #ZKMesh readers so far?

ZK Mesh Feb 2025 Top 5, here we go
🧡 πŸ‘‡

open.substack.com/pub/zkmesh/p...

17.03.2025 11:56 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Introduction - Halo Hero

damn this halo2 book is soooo goooood halo2.zksecurity.xyz/intro/

14.03.2025 15:53 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Coinbase phishing email tricks users with fake wallet migration A large-scale Coinbase phishing attack poses as a mandatory wallet migration, tricking recipients into setting up a new wallet with a pre-generated recovery phrase controlled by attackers.

A large-scale Coinbase phishing attack poses as a mandatory wallet migration, tricking recipients into setting up a new wallet with a pre-generated recovery phrase controlled by attackers.

14.03.2025 18:35 β€” πŸ‘ 7    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
Sepolia Pectra fork incident recap Blog on semi-cool ethereum stuff

Sepolia Pectra fork incident recap:
"we quickly realized that, because the deposit contract is token gated, an ERC-20 transfer event was emitted whenever a deposit was processed.
mariusvanderwijden.github.io/blog/2025/03...

13.03.2025 08:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Bybit hack deep dive by ncc group www.nccgroup.com/us/research-...

12.03.2025 07:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@ad403 is following 20 prominent accounts