techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

4.8K
active users

#github

230 posts106 participants11 posts today

⚠️ Sophos alerta: o trojan Sakura RAT no GitHub tem código com backdoor embutido que infecta quem tenta compilar.

🎯 Mais de 130 repositórios ligados ao mesmo autor, disfarçados como projetos legítimos, visam devs, gamers e pesquisadores.

🔗 news.sophos.com/en-us/2025/06/
#Malware #CyberSecurity #GitHub #Backdoor #Infosec

Damp black stone walls leading to a wooden door
Sophos News · The strange tale of ischhfd83: When cybercriminals eat their ownA simple customer query leads to a rabbit hole of backdoored malware and game cheats

The strange tale of ischhfd83: When cybercriminals eat their own

This investigation uncovered a large-scale campaign involving backdoored GitHub repositories targeting game cheaters and inexperienced cybercriminals. The threat actor, possibly linked to a Distribution-as-a-Service operation, uses multiple types of backdoors and a convoluted infection chain leading to RATs and infostealers. The campaign involves automated commits, obfuscation techniques, and complex payloads. Researchers found over 100 malicious repositories with distinct contributor roles, suggesting an automated framework. The eventual payload includes AsyncRAT, Remcos, and Lumma Stealer. The threat actor uses Telegram for notifications and various paste sites for hosting malicious code. This case highlights the complexity of modern cyber threats and the importance of cautious approaches to open-source repositories.

Pulse ID: 68409d66fe68571150ccaad4
Pulse Link: otx.alienvault.com/pulse/68409
Pulse Author: AlienVault
Created: 2025-06-04 19:24:22

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

I take back anything good that I’ve ever said about #AI or #copilot for #Github. It hallucinates to such a degree that it gets in the way more that helps. If I’m writing unit tests, then it’s typahead on steroids but anything else and it’s more of a problem than benefit. In the meantime, it’s destroying the planet with unnecessary computer usage. I think the models are beginning to collapse. I hope they collapse quickly.

New Open-Source Tool Spotlight 🚨🚨🚨

Groundhog by @ghuntley explains AI coding agents like Cursor from first principles. Built in Rust, it teaches the inner workings of coding assistants—perfect for learning or building your own. #AI #RustLang

🔗 Project link on #GitHub 👉 github.com/ghuntley/groundhog

#Infosec #Cybersecurity #Software #Technology #News #CTF #Cybersecuritycareer #hacking #redteam #blueteam #purpleteam #tips #opensource #cloudsecurity

✨
🔐 P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking 💻🏴‍☠️