AndrewMohawk
@andrewmohawk.bsky.social
📤 195
📥 173
📝 73
Just another noob.
Since i'm still on the hellsite, here is my thread on the NPM dependency issues:
x.com/AndrewMohawk...
But TL;DR there is so much FUD This would only impact you if -FRESH install between 9am-11.30am ET -OR Package-lock.json created in that time -Vuln packages in direct or transient dependencies
loading . . .
AndrewMohawk⁽ⁿᵘˡˡ⁾ on X: "Lot of chatter about the QIX NPM compromise. TL;DR -- Dev was compromised ~9am ET ( https://t.co/bgOwN57xyz ) -- Malicious packages removed at ~11.30 ET ( https://t.co/XApcXgcQoK ) If you installed in this time please check your codebase." / X
Lot of chatter about the QIX NPM compromise. TL;DR -- Dev was compromised ~9am ET ( https://t.co/bgOwN57xyz ) -- Malicious packages removed at ~11.30 ET ( https://t.co/XApcXgcQoK ) If you installed in this time please check your codebase.
https://x.com/AndrewMohawk/status/1965116722375209305
4 months ago
0
1
1
Feels so good to interact with the infosec community as a whole, I cant imagine why we have bad reputation as not being welcoming!
5 months ago
0
1
0
expel.com/blog/poisons...
pretty interesting using cross device sign in (
www.passkeycentral.org/design-guide...
) to bypass fido2 hurdle, effectively turning the hardware token into QR code and asking the user to scan it
5 months ago
0
1
0
I made a submission!
6 months ago
0
3
0
reposted by
AndrewMohawk
Kym Possible
6 months ago
My firstborn is trans 🏳️⚧️ nonbinary ⚧️ and a tattoo artist that now lives in California. They’re in Seattle for their brother’s graduation this week and brought their gear to give me a tattoo. There is a my other two tattoos are decorative but there is a meaningful story behind what I had them do. 1/
1
26
1
reposted by
AndrewMohawk
David Buchanan
7 months ago
here's a framebuffer graphics demo (this has no practical purpose and I can't prove I'm not just like, playing a youtube video or something)
loading . . .
31
1283
330
Finally one of the models is useful to me. I give you my stance on WebAuthN. cc @Yubico (Everyone at orgs I work at has a 5C + 5C NFC for phone and your org should as well)
7 months ago
0
0
0
Whats the worst that could happen?
7 months ago
0
0
0
reposted by
AndrewMohawk
Jake
8 months ago
Its finders keepers for one of these f-18s right?
29
401
19
@kurtopsahl.bsky.social
just said "The journey to stronger opsec begins with reducing the number of steps" and I fucking love it.
8 months ago
0
2
1
reposted by
AndrewMohawk
Red Durkin
8 months ago
She thinks the Library of Congress is like a local public library because it's got "Library" in the name and I can't emphasize enough that our country is being run by the stupidest people alive on the planet today.
add a skeleton here at some point
17
1087
236
reposted by
AndrewMohawk
Blaise Ulysse Bernard Collins
9 months ago
116
7335
1710
You wont know when I am absolutely destroying my docker swarm, but there will be signs.
9 months ago
0
0
0
I got Manus access and errr.. its struggling with a docker project, but the filenames are hilarious! Manus.. its just like us!
9 months ago
0
0
0
The life of crime is calling me!
9 months ago
0
3
0
Another day, another 9.x critical vuln that bypasses authentication/authorization flow :(
thehackernews.com/2025/03/crit...
But dont worry it's just the kubes ingress-nginx and not the nginx ingress controller often used for kubes. Stay safe out there 🙃
loading . . .
Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
Five critical flaws in Ingress NGINX Controller expose 6,500+ clusters; update now to prevent unauthorized remote code execution.
https://thehackernews.com/2025/03/critical-ingress-nginx-controller.html
9 months ago
0
0
0
Meme stolen from
@yaelwrites.com
add a skeleton here at some point
9 months ago
1
8
1
reposted by
AndrewMohawk
Shane Harris
9 months ago
In 25 years of covering national security, I’ve never seen a story like this: Senior Trump officials discussed planning for the U.S. attack on Yemen in a Signal group--and inadvertently added the editor-in-chief of The Atlantic.
www.theatlantic.com/politics/arc...
loading . . .
The Trump Administration Accidentally Texted Me Its War Plans
U.S. national-security leaders included me in a group chat about upcoming military strikes in Yemen. I didn’t think it could be real. Then the bombs started falling.
https://www.theatlantic.com/politics/archive/2025/03/trump-administration-accidentally-texted-me-its-war-plans/682151/?gift=kPTlqn0J1iP9IBZcsdI5IVJpB2t9BYyxpzU4sooa69M&utm_source=copy-link&utm_medium=social&utm_campaign=share
787
16662
9114
Found a cool animatronic eye 3D print and spent the weekend making it follow me around
loading . . .
9 months ago
3
4
1
I really hate that this is the release details we get for a *9.1 critical vuln* in a common js stack:
www.cve.org/CVERecord?id...
I will be blocking all requests with the header `x-middleware-subrequest` rather than risk deploying a > 5pm release for something without any real details.
loading . . .
Common vulnerabilities and Exposures (CVE)
https://www.cve.org/CVERecord?id=CVE-2025-29927
9 months ago
0
1
0
Tornado cash is back.
home.treasury.gov/news/press-r...
loading . . .
Tornado Cash Delisting
WASHINGTON — Based on the Administration’s review of the novel legal and policy issues raised by use of financial sanctions against financial and commercial activity occurring within evolving technolo...
https://home.treasury.gov/news/press-releases/sb0057
9 months ago
0
0
0
Vibe coding my own rust ui for the rayhunter (
github.com/EFForg/rayhu...
)
9 months ago
1
2
1
A short story in 4:
10 months ago
0
1
1
Twitter is down! Maybe DOGE finally did something people agree with
10 months ago
0
1
0
Looking at some of the other recent DPRK attacks I noticed docker being used with `--privileged` flag. I also know that on mac there is a current issue with docker (
github.com/docker/for-m...
) and the workaround is to move things to /Library/PrivilegedHelperTools/.
10 months ago
1
0
0
Whats the best way for me to post things to both bluesky and the dark site whose name we do not mention?
10 months ago
2
2
1
I put up a few words about the recent Bybit hack, I got so annoyed with companies shilling solutions or punching down. As a security community we should be and expect better.
privy.io/blog/bybit-l...
loading . . .
Privy Blog | On hindsight and risk assessment
https://privy.io/blog/bybit-lookback
10 months ago
0
1
0
Reminder that bybit is not the first nor likely the last attack we will see using this method-similar to previous attacks: DMM ($308m, May 2024) WazirX ($230m, July 2024) Radiant ($55m, Oct 2024)
medium.com/@RadiantCapi...
www.fbi.gov/news/press-r...
www.liminalcustody.com/blog/update-...
loading . . .
Radiant Capital Incident Update
2024–12–06
https://medium.com/@RadiantCapital/radiant-capital-incident-update-e56d8c23829e
10 months ago
0
2
1
reposted by
AndrewMohawk
The Tennessee Holler
10 months ago
WYOMING: “Thank you, Madam chairman.” “I prefer ‘Mister’ chairman.” “Well you all voted preferred pronouns cannot be compelled speech.”
loading . . .
1432
40430
11583
9gb? what exactly is going on with
@burpsuite.bsky.social
these days! I just restarted it and im browsing a local next js app!
11 months ago
1
2
0
reposted by
AndrewMohawk
Sonia Cuff
11 months ago
Rest in peace:
0
185
33
I dont often have to help someone secure outlook, mostly deal with Google workspace, but I found this guide really well done. Props to Australian Signals Directorate for actionable security. Gold security star.
www.cyber.gov.au/sites/defaul...
loading . . .
https://www.cyber.gov.au/sites/default/files/2023-04/ACSC%20Step%20by%20Step%20Guide%20-%20Email%20Security%20Outlook.pdf
11 months ago
0
1
0
www.cell.com/device/fullt...
Okay I really want one.
loading . . .
SpiRobs: Logarithmic spiral-shaped robots for versatile grasping across scales
SpiRobs morphologically replicate the logarithmic spiral that is ubiquitous in natural organisms. They are easy and fast to build across scales via 3D printing. They are actuated by cables, which allo...
https://www.cell.com/device/fulltext/S2666-9986(24)00603-3?rss=yes&utm_source=dlvr.it&utm_medium=linkedin#fig4
11 months ago
0
0
0
gist.github.com/hackermondev...
Fun writeup on figuring out cloudflare traffic!
loading . . .
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform - research.md
https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117
11 months ago
0
3
3
reposted by
AndrewMohawk
Ron’s Computer Videos 🧍♂️🖥️📼
11 months ago
I wonder how much of this is Luigi related?
2
14
3
This is simply a super useful free tool, if you are using github and not running this you are making life more difficult for yourself
add a skeleton here at some point
11 months ago
0
1
0
I will kill for these 3!
12 months ago
0
1
0
reposted by
AndrewMohawk
Jerry Chen
12 months ago
why'd they name this app bluesky when Elders Scroll was right there
263
7726
675
reposted by
AndrewMohawk
posts inspector
12 months ago
for anybody wondering what the flag will look like if we added greenland as a state
147
2575
174
reposted by
AndrewMohawk
Madeley
12 months ago
Being sentient is so weird. You run an electrical charge through some meat and suddenly anxiety exists.
49
2935
432
Nvidia really letting rip at CES2025! Damn, I want all their things
12 months ago
0
1
0
Here. The elevators, the number order? 1,3,2,5,4 of course.
12 months ago
0
0
0
reposted by
AndrewMohawk
S🌟tella
12 months ago
A simple way to let go of the past and redirect your negative energy is to add more cheese to your pasta
97
3446
551
reposted by
AndrewMohawk
Cats and Fortunes
12 months ago
You'll feel much better once you've given up hope.
0
1
1
Feature request for venmo: give us a random emoji option so service workers don't have to do this (or heck, pay people so they don't rely on tips!)
12 months ago
1
1
0
The simpler times
en.wikipedia.org/wiki/MOPy_fish
loading . . .
MOPy fish - Wikipedia
https://en.wikipedia.org/wiki/MOPy_fish
about 1 year ago
0
1
0
reposted by
AndrewMohawk
Filippo Valsorda
about 1 year ago
6
1121
222
This is some totally fun research by
@d4d89704243.bsky.social
on manipulating cookies and how (once again) HTTP is implemented so vastly different across clients! Would love to see what the js servers do since they seem to be everywhere now
add a skeleton here at some point
about 1 year ago
0
1
0
If you need to know more about me.
about 1 year ago
0
1
0
Load more
feeds!
log in