π’ We're exhibiting at the International Cyber Expo to showcase our programmes, projects and insights to help organisations innovate and collaborate in todayβs evolving security landscape!
Enquire to access the engaged #ICE2025 audience with your solutions: hubs.la/Q03vC9yy0
05.09.2025 12:02 β π 1 π 1 π¬ 0 π 0
New Blog: Nx Package Compromise
Malware hidden in recent Nx releases created a repo called s1ngularity-repository in developersβ GitHub accounts exposing SSH keys, API tokens, and even wallet files.
Read the breakdown + what to do next: ossprey.com/blog/nx-pack...
#SupplyChainSecurity #npm #OSS
28.08.2025 09:17 β π 0 π 0 π¬ 0 π 0
OSSPREY
Published on August 24, 2025
New from Ossprey: PyPI is cracking down on domain resurrection attacks by invalidating expired maintainer domains.
1,800 accounts un-verified in just 2 months.
Time to check if your dependencies rely on revoked maintainers.
Full blog: ossprey.com/blog/pypi-domain-vigilance
#opensourcesecurity
26.08.2025 09:00 β π 0 π 0 π¬ 0 π 0
π New Case Study: How is Google securing the future of machine learning?
By partnering with #sigstore and the Open Source Security Foundation (OpenSSF), theyβve implemented model signing that makes AI systems more trustworthy by default.
openssf.org/blog/2025/07...
28.07.2025 19:13 β π 5 π 3 π¬ 0 π 1
Wild times! π¨ Cybercrime meets geopoliticsβ$1M stolen by North Korean hackers. This underscores the urgent need for robust security in crypto. Time to bolster defenses! ππ° #CryptoSecurity #Innovation
04.07.2025 07:54 β π 1 π 1 π¬ 0 π 0
Talks from the Purdue CERIAS 2025 Cybersecurity Symposium, which took place at the start of April, are available on YouTube
www.youtube.com/playlist?lis...
www.youtube.com/playlist?lis...
02.07.2025 21:41 β π 3 π 3 π¬ 0 π 0
GitLab catches MongoDB Go module supply chain attack
Learn how GitLab detected a supply chain attack targeting Go developers through fake MongoDB drivers that deploy persistent backdoor malware.
"Software supply chain attacks via malicious dependencies continue to be one of the most significant security threats to modern software development"
Kudos to our friends over at @gitlab.com for the solid detection and writeup!
about.gitlab.com/blog/gitlab-...
01.07.2025 01:00 β π 0 π 0 π¬ 0 π 0
Threat Actors Attacking Cryptocurrency and Blockchain Developers with Weaponized npm and PyPI Packages - Bytes Europe
The cryptocurrency and blockchain development ecosystem is facing an unprecedented surge in sophisticated malware campaigns targeting the open source supply
Threat Actors Attacking Cryptocurrency and Blockchain Developers with Weaponized npm and PyPI Packages
https://www.byteseu.com/1103527/
The cryptocurrency and blockchain development ecosystem is facing an unprecedented surge in sophisticated malware campaigns targeting the open source supply β¦
14.06.2025 07:52 β π 1 π 1 π¬ 0 π 0
OSSPREY
Published on April 11, 2025
π¨ Supply Chain Security in Focus
See our latest blog post for a technical deep dive into what happened and what it means for engineers and defenders.
π ossprey.com/blog/tj-acti...
Let us know your thoughts or what your team is doing to reduce this kind of risk.
#ossprey #BirdsOfCyber
22.04.2025 07:08 β π 1 π 0 π¬ 0 π 0
OSSPREY
Published on April 15, 2025
In the era of AI assistants and vibe coding, a new threat emerges from the shadows. It has lurked, hidden and patient, waiting for the right moment.
Zombie Dependencies: theyβre not after brainsβ¦ theyβre after your code. :π§ π»
Read the full post here
π ossprey.com/blog/zombie-...
17.04.2025 07:22 β π 1 π 0 π¬ 0 π 0
Band wagons are for hopping on, right? Especially if they're easy and fun!
So, everyone, meet Ozzy the Ossprey! He's a lean, mean malware-fighting machine that's here to stomp out open source malware!
Get this limited edition Ozzy the Ossprey in a package manager near you!
#BirdsOfCyber #Ossprey
14.04.2025 07:19 β π 2 π 1 π¬ 1 π 0
Blog | OSSPREY
π Read our blog here : ossprey.com/blog/ π
Massive thanks to Plexal, Department of Science, Technology and Innovation, our mentors, and the incredible UK cyber community for backing bold ideas.
11.04.2025 11:32 β π 2 π 1 π¬ 0 π 0
π¦
Last month, OSSPREY graduated from both Cyber Runway!
What started as an idea in a bootcamp is now a full-flight cybersecurity startup with a beta product that hunts for malware in open source.
Over 60 sessions. 6 cities. Countless insights.
π₯ Top takeaways - Build fast, Validate faster.
π§΅
11.04.2025 11:30 β π 1 π 1 π¬ 1 π 0
I'm a reluctant technologist comfortable in C/C++, Python, JavaScript, and Rust. Currently working in satellite navigation, but I've built everything from flight [β¦]
π bridged from β https://fosstodon.org/@bckohan, follow @ap.brid.gy to interact
Sr. Threat Intelligence Consultant @NCCGroupplc | Ex Org @bsidesncl | ThreatIntel | Views are my own
Co-founder at @BotCity (YC W22)
OSS Maintainer at MarvinJ and Marvin
Computer Scientist, AI, Open Source
Building AGI with Privacy and Security at OpenAI.
Previously: ML Supply chain security @ Google OSS Security Team (model signing, GUAC).
Previously: TensorFlow Security & OSS (@ Google)
Previously: Haskell+differential privacy+ML @ LeapYear
Protects. Secures. Insures. Delivering world-class device protection, security and insurance via our app in minutes.
yourfortress.com
π Santa Monica, California
We're the innovation and growth company helping to strengthen the UKβs technology capabilities through collaboration with government, startups, industry and academia.β
https://www.plexal.comβ
https://linktr.ee/Plexal
he/they | Junior Software Engineer | VR Enthusiast
https://thevirusofdoom.xyz/
runner / cyber security guy / aging punk / baltimorean
https://linktr.ee/mcflynnthm
The largest collection of malware source code, samples, and papers on the internet.
Password: infected
(unofficial, this is a bot! Maintained by @yjb.bsky.social, the bot can't handle retweets, video, and maybe a few other things)
Mom // software engineer // developer stuff @ aws
Iβm Scout β your AI sidekick for threat hunting.
I help analysts ask better questions, follow the trail, and never lose context.
Built by Huntbase to think like a human, not a rule engine.
π https://www.huntbase.io
π¦ Node.js Secure Coding: http://nodejs-security.com
π @GitHub Star
π
@OpenJS Pathfinder award for Security
π₯ DevRel at @snyksec
JavaScript / software engineer focused on green tech. Outdoor enthusiast based in Boulder, CO, originally from Germany. Passionate about sustainability and the great outdoors.
A podcast about developer tools by @just-be.dev and @hipstersmoothie.com.
https://devtools.fm
A person trying to leave things better than I found them. π
Appalachian born, Cascadia based. π²
Software Engineer and AWS Hero. π»
Technologist | Speaker | Author | AWS Serverless Hero | Team Topologies Advocate | Serverless Development on AWS (O'Reilly) | Speak Effectively At Conferences
https://sheenbrisals.com
Cloud and container security β’ Security research and open source at Datadog
π¨ππ«π·
https://christophetd.fr