ClickFix Exploits Homebrew Workflow to Deploy Cuckoo Stealer for macOS Credential Theft
ClickFix is being weaponized against macOS developers by turning a trusted Homebrew workflow into a stealthy delivery channel for a new infostealer dubbed Cuckoo Stealer.
Mac users, be careful when you install HomeBrew.
"The attack starts with typosquatted domains that closely mimic the official Homebrew site, including homabrews[.]org and other lookalike hostnames served from shared infrastructure at 5.255.123[.]244. β"
gbhackers.com/clickfix-exp...
18.02.2026 15:27 β π 0 π 0 π¬ 0 π 0
I've been looking forward to @zephrfish.yxz.red's new course, Malwareless Adversarial Emulation. Just by looking at the course syllabus, I'm confident I'm going to learn a ton and become a better operator. And the price to value is more than reasonable.
The course is at lms.zsec.red
14.02.2026 19:06 β π 2 π 2 π¬ 1 π 0
I've been looking forward to @zephrfish.yxz.red's new course, Malwareless Adversarial Emulation. Just by looking at the course syllabus, I'm confident I'm going to learn a ton and become a better operator. And the price to value is more than reasonable.
The course is at lms.zsec.red
14.02.2026 19:06 β π 2 π 2 π¬ 1 π 0
How AI coding agents workβand what to remember if you use them
From compression tricks to multi-agent teamwork, here's what makes them tick.
I feel like @benjedwards.com has written one of the best explanations of how AI coding agents work. The article breaks it down into easy to understand terms that developers new to agents can really grok.
arstechnica.com/information-...
29.12.2025 21:43 β π 8 π 3 π¬ 1 π 0
WebRAT malware spread via fake vulnerability exploits on GitHub
The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-conceptΒ exploits for recently disclosed vulnerabilities.
ALWAYS validate proof-of-concept exploit code before you use it.
"The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities."
www.bleepingcomputer.com/news/securit...
24.12.2025 20:10 β π 0 π 0 π¬ 0 π 0
I hate scammers.
14.12.2025 02:26 β π 3 π 0 π¬ 0 π 0
What do I do on the weekend? I install Game of Active Directory Ninja Hacker Academy on AWS of course! π
I'm running through the install so I can learn more about the range deployment on cloud services. Always be learning something new. @orangecyberdefense.bsky.social
github.com/Orange-Cyber...
07.12.2025 04:41 β π 0 π 0 π¬ 0 π 0
Glad to help shine more light on the great work you're doing to help bring affordable security education to folks. β€οΈ
02.12.2025 18:08 β π 1 π 0 π¬ 0 π 0
Always a pleasure. Keep providing great learning materials and making these important tools accessible. It's appreciated.
02.12.2025 18:07 β π 1 π 0 π¬ 0 π 0
YouTube video by Rey Bango
Get the latest Black Friday and Cyber Monday Cybersecurity Deals for 2025!
Black Friday and Cyber Monday deals are out! I review some of them and link to a community GitHub page for you all to get discounts on courses, tools and services!
Deals from
@rastamouse.me, OffSec, EvilGinx, @antisyphontraining.bsky.social
and a whole lot more.
youtu.be/hkJfhM1T5bI
30.11.2025 16:11 β π 3 π 0 π¬ 2 π 0
a man is standing in front of a microphone with the words `` help me '' written on it .
ALT: a man is standing in front of a microphone with the words `` help me '' written on it .
Seeking video camera advice for content creation.
I've gotten back to creating tutorial & teaching videos on YouTube. Currently using a Brio MX but interested in the @elgato Facecam 4K. It looks to offer a lot more software features.
Has anyone used it & can give their thoughts?
05.10.2025 20:31 β π 0 π 0 π¬ 0 π 0
YouTube video by Rey Bango
Did I Just Fall for a Phishing Attempt?
After getting a scam email saying someone tried to access my Twitter account, I decided to look into it a little. The first of many new videos to come as I work to share more information with the community.
youtu.be/IFy_96Dg__E?...
26.09.2025 17:09 β π 1 π 0 π¬ 1 π 0
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security Changes
RubyGems and PyPI hit by credential-stealing packages targeting automation and crypto users, prompting new security rules.
RubyGems & PyPI under attack:
πΈ 60 fake RubyGems stole social media logins (275K+ downloads)
πΈ PyPI fakes hijacked crypto staking wallets
Both hide credential-stealing code in legit-looking packages. #CyberAlerts thehackernews.com/2025/08/ruby...
08.08.2025 21:30 β π 4 π 4 π¬ 0 π 1
A black-and-white satirical cartoon on a plain white background, depicting the progressive decay of the Apple company logo as it transforms into a silhouette of Donald Trumpβs head, symbolizing Appleβs βfallβ or moral compromise due to a gift from Tim Cook to Trump that many critics viewed as resembling a bribe to secure tariff exemptions. 2 0 1 Five solid black silhouettes of apples are arranged in a diagonal line descending from top-left to bottom-right, each showing increasing damage as if being eaten or rotting away: the first is the intact Apple logo with a small bite on the right side and a leaf on top; the second has a larger bite; the third is more eroded; the fourth appears partially exploded or flowered open; and the fifth is heavily disintegrated into petal-like fragments that form a caricatured profile of Trump, complete with his distinctive comb-over hairstyle. In the top-right corner, handwritten text reads βThe Buffalo News Adam Zyglis Cartoonist /2023/ something,β suggesting a commentary on decline or downfall tied to this controversial gestureβa commemorative glass plaque with a 24k gold base, engraved as a memento of the first US-made Mac Pro, offered amid discussions on trade policies.
08.08.2025 23:31 β π 364 π 99 π¬ 19 π 4
Hi @defcon.bsky.social
07.08.2025 23:08 β π 0 π 0 π¬ 0 π 0
Picked up this very cool @crowdstrike.com t-shirt for my son and the action figure that goes with it. Heβs going to love it.
06.08.2025 22:40 β π 0 π 0 π¬ 0 π 0
@crowdstrike.com says theyβre seeing threat actors are targeting GenAI workloads to try poison the models. The inherent trust being built as we continue to use AI systems will lead to threat actors becoming an insider threat.
06.08.2025 18:43 β π 0 π 0 π¬ 0 π 0
Walking back to my room I passed the Google Cloud Security party at Blackhat and it looked jumping. Almost considered social engineering my way in. ππ
06.08.2025 02:16 β π 1 π 0 π¬ 0 π 0
Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem
PXA Stealer uses advanced evasion and Telegram C2 to steal global victim data, fueling a thriving cybercrime market.
Great analysis by @SentinelOne on a threat actor working out of Vietnam to target users in 62 countries.
Starts with a phishing campaign that leads to DLL sideloading of legitimate and signed software, including Office 2013, for persistence.
www.sentinelone.com/labs/ghost-i...
05.08.2025 16:46 β π 1 π 1 π¬ 0 π 0
ππkerberoasting 4eva amirite @timmedin.bsky.social
05.08.2025 16:02 β π 1 π 0 π¬ 0 π 0
hashcat v7.0.0
Hashcat v7.0.0 released with speed and GPU support improvements
hashcat.net/forum/thread...
04.08.2025 17:56 β π 0 π 0 π¬ 0 π 0
"Wo unto you rich men, that will not give your substance to the poor, for your riches will canker your souls; and this shall be your lamentation in the day of visitation, and of judgment, and of indignation: The harvest is past, the summer is ended, and my soul is not saved!"
02.06.2025 01:19 β π 2 π 1 π¬ 0 π 0
A Reality Show Where Immigrants Compete for U.S. Citizenship? D.H.S. Is Considering It.
βThis isnβt 'The Hunger Gamesβ for immigrants,β Worsoff told the newspaper
This absolutely disgusting and a pathetic way of taking advantage of immigrants by this producer.
www.nytimes.com/2025/05/16/u...
17.05.2025 22:57 β π 0 π 0 π¬ 0 π 0
a pixelated image of a little girl in a red coat
ALT: a pixelated image of a little girl in a red coat
When you play an internal CTF against 10 other teams and win! Booyah! π
07.05.2025 22:46 β π 0 π 0 π¬ 0 π 0
18.04.2025 21:51 β π 1 π 0 π¬ 1 π 0
Armchair Data Scientist and nerd. PhD in automated theorem proving just before AI became a subfield of Linear Algebra. Machine Learning, statistics, data visualisation, biology, recreational maths, computation, old pocket calculators, and video games
Senior AI Reporter, Ars Technica. Tech Historian. Bylines Fast Company / The Atlantic / Retronauts. http://www.benjedwards.com Founder http://Vintagecomputing.com
News, insights, trends and product info in the security industry for security suppliers, end users and IT decision-makers.
https://securitytoday.com/Home.aspx
I play with vulnerabilities and exploits, but am forbidden to discuss such things publicly.
I used to be https://twitter.com/wdormann but Twitter has become [β¦]
π bridged from https://infosec.exchange/@wdormann on the fediverse by https://fed.brid.gy/
I play with vulnerabilities and exploits.
While this site initially showed promise, I've grown tired with its lack of improvement.
You'll find me @wdormann@infosec.exchange on Mastodon.
APAC IT Manager for a global business, which has absolutely nothing to do with my posts. An eclectic mix of any damn thing I want.
Advocate | Agitator | Organizer | Activist
Defend Freedom | Nurture Earth | Do Good
#3E #BindingChaos #Op3E #OpEyesUp
ReversingLabs is the trusted name in file and software security.
RL - Trust Delivered.
@defcon.bsky.social Speaker Ops #Goon, DEFCON.social moderator, @BSidesCharm.bsky.social and @bsidesphilly.bsky.social organizer, CISSP, MCSE, Xbox Gamer
Father π
ββοΈπ
ββοΈ Dev & Cyber, I like computers and tech π» Lifelong learner π Respect for Life and Diversity. Living and learning. Views are my own.
Blue Teamer in Disguise. Blog at http://netsecfocus.com. SANS Netwars Champion. Former community manager and founder of the Offsec community for @offsectraining
Software craftsman. Mozilla CPO. Former Twitter, Meta, Microsoft. Seattle-based, Bay Area bred.
Interested in AI/ML security, vulnerability research, rust, fuzzing, offensive security, and reversing.
In my spare (computer-related) time, I maintain feroxbuster and feroxfuzz as well as contribute to and/or maintain various other open source projects.
AppSec pentester type at
TrustedSec.
Beach bum. Super awesome dad.
Coder of weird things.
https://github.com/hoodoer
Picture taker of nature and wildlife
Lover of birds and pretty sights
Clicker of links
Leader of incidents
Keeper of horrible hours
Advocator of equality
Practicer of kindness
Preferrer of big forks/small spoons
User of turn signals
www.shawnthomas.art
Penetration Tester | Breaking all the things & fixing things for a living | eCPPTv2
πΎ console cowboy in cyberspace
π» Engineering leader in NYC
π¦ Vanilla JavaScript
π« Chocolate HTML
π Strawberry CSS
βΎοΈ Mets
π Liberty
Enjoy yourself - it's later than you think.
Real-time historian of the late cyber capitalist era @TechCrunch, writing about the intersection of hackers, human rights, and spies.
Also writing a book about Hacking Team and the history of government spyware.
βοΈ Signal: +1 917 257 1382
Former product manager for VMware Fusion and Workstation
Love playing guitar, stage or street acting, woodworking, growing fruit trees, making olives.