Sign in

p80n-sec

@p80n-sec.bsky.social
1 followers 2 following 1 posts

Security Researcher

PostsRepliesMedia
Reposted by p80n-sec
Endor Labs @endorlabs.bsky.social · 18/08/2026
@p80n-sec.bsky.social audited 7 AI orchestration platforms and found 14 xritical + high severity vulns, including multiple unauthenticated prompt injection → RCE chains. Full research from DEFCON 34: www.endorlabs.com/learn/hackin...
endorlabs.com
Hacking your life with AI can get you hacked | Blog | Endor Labs
Hacking your life with AI can get you hacked
011
Reposted by p80n-sec
Endor Labs @endorlabs.bsky.social · 17/06/2026
116 @mastra npm packages trojanized in 27 minutes via a hijacked account. Tens of millions of downloads at risk. The malware is in easy-day-js, a typosquat added as a dependency. Dropper disables TLS, fetches remote payload, self-deletes. Full IOCs + remediation: 🔗 www.endorlabs.com/learn/mastra...
endorlabs.com
Mastra npm Org Compromised: Multiple Packages Trojanized to Drop a Remote Payload via easy-day-js | Blog | Endor Labs
A single hijacked maintainer account pushed multiple trojanized packages across the entire @mastra scope in 27 minutes, each carrying a typosquat dependency that runs a remote payload on install. Comb...
011
p80n-sec @p80n-sec.bsky.social · 04/06/2026
ai-sdk-ollama versions 3.8.5, 2.2.1, 1.1.1, and 0.13.1 have clear evidence of malicious credential stealers with the potential of worming in this latest supply chain compromise Here's the full analysis and I'll make updates as they come
000