home.social

#megalodon — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #megalodon, aggregated by home.social.

  1. A simple repair job at home should be easy and accessible. Whether you've got a new shelf to put together or an old dishwasher that needs some TLC, Megalodon is packed to the gills with practicality for all those everyday household projects.

    ifixit.com/products/megalodon-

    #iFixit #RightToRepair #Megalodon #FixItYourself #RepairDontReplace #DIYRepair

  2. A simple repair job at home should be easy and accessible. Whether you've got a new shelf to put together or an old dishwasher that needs some TLC, Megalodon is packed to the gills with practicality for all those everyday household projects.

    ifixit.com/products/megalodon-

    #iFixit #RightToRepair #Megalodon #FixItYourself #RepairDontReplace #DIYRepair

  3. 5,7 tys. commitów w 6 godzin. Repozytoria GitHub zainfekowane w kampanii “megalodon”

    Badacze z SafeDep wykryli zautomatyzowaną kampanię – nazwaną megalodon – w ramach której wypchnięto ponad 5,7 tysięcy złośliwych commitów w ponad 5,5 tysiącach repozytoriów na GitHub. Całość zajęła ~6 godzin. Korzystając z jednorazowych kont atakujący wstrzyknęli złośliwe workflow GitHub Actions zawierające zakodowane w base64 payloady (bash), które wykradają sekrety CI,...

    #Aktualności #Bezpieczeństwo #Github #Kampania #Megalodon

    sekurak.pl/57-tys-commitow-w-6

  4. 5,7 tys. commitów w 6 godzin. Repozytoria GitHub zainfekowane w kampanii “megalodon”

    Badacze z SafeDep wykryli zautomatyzowaną kampanię – nazwaną megalodon – w ramach której wypchnięto ponad 5,7 tysięcy złośliwych commitów w ponad 5,5 tysiącach repozytoriów na GitHub. Całość zajęła ~6 godzin. Korzystając z jednorazowych kont atakujący wstrzyknęli złośliwe workflow GitHub Actions zawierające zakodowane w base64 payloady (bash), które wykradają sekrety CI,...

    #Aktualności #Bezpieczeństwo #Github #Kampania #Megalodon

    sekurak.pl/57-tys-commitow-w-6

  5. 5,7 tys. commitów w 6 godzin. Repozytoria GitHub zainfekowane w kampanii “megalodon”

    Badacze z SafeDep wykryli zautomatyzowaną kampanię – nazwaną megalodon – w ramach której wypchnięto ponad 5,7 tysięcy złośliwych commitów w ponad 5,5 tysiącach repozytoriów na GitHub. Całość zajęła ~6 godzin. Korzystając z jednorazowych kont atakujący wstrzyknęli złośliwe workflow GitHub Actions zawierające zakodowane w base64 payloady (bash), które wykradają sekrety CI,...

    #Aktualności #Bezpieczeństwo #Github #Kampania #Megalodon

    sekurak.pl/57-tys-commitow-w-6

  6. 5,7 tys. commitów w 6 godzin. Repozytoria GitHub zainfekowane w kampanii “megalodon”

    Badacze z SafeDep wykryli zautomatyzowaną kampanię – nazwaną megalodon – w ramach której wypchnięto ponad 5,7 tysięcy złośliwych commitów w ponad 5,5 tysiącach repozytoriów na GitHub. Całość zajęła ~6 godzin. Korzystając z jednorazowych kont atakujący wstrzyknęli złośliwe workflow GitHub Actions zawierające zakodowane w base64 payloady (bash), które wykradają sekrety CI,...

    #Aktualności #Bezpieczeństwo #Github #Kampania #Megalodon

    sekurak.pl/57-tys-commitow-w-6

  7. 5,7 tys. commitów w 6 godzin. Repozytoria GitHub zainfekowane w kampanii “megalodon”

    Badacze z SafeDep wykryli zautomatyzowaną kampanię – nazwaną megalodon – w ramach której wypchnięto ponad 5,7 tysięcy złośliwych commitów w ponad 5,5 tysiącach repozytoriów na GitHub. Całość zajęła ~6 godzin. Korzystając z jednorazowych kont atakujący wstrzyknęli złośliwe workflow GitHub Actions zawierające zakodowane w base64 payloady (bash), które wykradają sekrety CI,...

    #Aktualności #Bezpieczeństwo #Github #Kampania #Megalodon

    sekurak.pl/57-tys-commitow-w-6

  8. This is not about the nature of "AI", it is about the corporations who are building it. These corporations are well within the definition of pleonexia: those who take more than their fair share.

    They are taking far more than their fair share of money, of the earth's resources, and now they are taking more than their fair share of our data, of the stories of our lives.

    They are hooking the mobile phone users into a common nervous system, with them the center.

    This development is very obvious to those who have access to the concepts of system network design.

    The "loci of agency and intent" model of the central actor in social and political contexts, is a mathematical form, and so it is scale invariant. If you find anything like such a locus, feel free to go ahead and give it a name, as its form will be relatively stable over time.

    Here such loci live in the waters of the global financial systems, megalodons who swim in the same substance as the minnows.

    The minnows never notice. And if they notice the shadow, they have little real concept of what it is thinking.

    #ai #fascists #megalodon

  9. This is not about the nature of "AI", it is about the corporations who are building it. These corporations are well within the definition of pleonexia: those who take more than their fair share.

    They are taking far more than their fair share of money, of the earth's resources, and now they are taking more than their fair share of our data, of the stories of our lives.

    They are hooking the mobile phone users into a common nervous system, with them the center.

    This development is very obvious to those who have access to the concepts of system network design.

    The "loci of agency and intent" model of the central actor in social and political contexts, is a mathematical form, and so it is scale invariant. If you find anything like such a locus, feel free to go ahead and give it a name, as its form will be relatively stable over time.

    Here such loci live in the waters of the global financial systems, megalodons who swim in the same substance as the minnows.

    The minnows never notice. And if they notice the shadow, they have little real concept of what it is thinking.

    #ai #fascists #megalodon

  10. 🕵🏻‍♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.

    #Megalodon backdoored 5,500 #GitHub repositories in six hours. Not six days — six hours. Malicious commits silently replacing CI/CD workflows, hoovering tokens, cloud credentials, SSH keys, and environment variables before most of the affected projects had processed a single alert. The same week, #IBM and #RedHat announced a $5 billion commitment, called Project Lightwell, to securing the open source supply chain, #Anthropic's #Mythos model surfaced 23,000 potential vulnerabilities across 1,000 OSS projects, and Apple open-sourced its quantum-resistant crypto stack with formal verification proofs attached. The industry's response to supply chain risk is finally arriving at a scale that looks serious.

    The problem is the math. The response is measured in billions of dollars and multi-year programs. The attack is measured in hours and automated tooling. Megalodon's six-hour window isn't an anomaly — it's a benchmark. Last week it was TeamPCP and the GitHub cascade. The week before, Laravel Lang and malicious postinstall hooks across 700 repos. The investment in defense is real and necessary, but it's being deployed against a threat that doesn't need a budget cycle to iterate. Project Lightwell will fund important work. Megalodon already shipped.

    → Week #22/2026 also covers: #ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  11. 🕵🏻‍♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.

    #Megalodon backdoored 5,500 #GitHub repositories in six hours. Not six days — six hours. Malicious commits silently replacing CI/CD workflows, hoovering tokens, cloud credentials, SSH keys, and environment variables before most of the affected projects had processed a single alert. The same week, #IBM and #RedHat announced a $5 billion commitment, called Project Lightwell, to securing the open source supply chain, #Anthropic's #Mythos model surfaced 23,000 potential vulnerabilities across 1,000 OSS projects, and Apple open-sourced its quantum-resistant crypto stack with formal verification proofs attached. The industry's response to supply chain risk is finally arriving at a scale that looks serious.

    The problem is the math. The response is measured in billions of dollars and multi-year programs. The attack is measured in hours and automated tooling. Megalodon's six-hour window isn't an anomaly — it's a benchmark. Last week it was TeamPCP and the GitHub cascade. The week before, Laravel Lang and malicious postinstall hooks across 700 repos. The investment in defense is real and necessary, but it's being deployed against a threat that doesn't need a budget cycle to iterate. Project Lightwell will fund important work. Megalodon already shipped.

    → Week #22/2026 also covers: #ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  12. 🕵🏻‍♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.

    #Megalodon backdoored 5,500 #GitHub repositories in six hours. Not six days — six hours. Malicious commits silently replacing CI/CD workflows, hoovering tokens, cloud credentials, SSH keys, and environment variables before most of the affected projects had processed a single alert. The same week, #IBM and #RedHat announced a $5 billion commitment, called Project Lightwell, to securing the open source supply chain, #Anthropic's #Mythos model surfaced 23,000 potential vulnerabilities across 1,000 OSS projects, and Apple open-sourced its quantum-resistant crypto stack with formal verification proofs attached. The industry's response to supply chain risk is finally arriving at a scale that looks serious.

    The problem is the math. The response is measured in billions of dollars and multi-year programs. The attack is measured in hours and automated tooling. Megalodon's six-hour window isn't an anomaly — it's a benchmark. Last week it was TeamPCP and the GitHub cascade. The week before, Laravel Lang and malicious postinstall hooks across 700 repos. The investment in defense is real and necessary, but it's being deployed against a threat that doesn't need a budget cycle to iterate. Project Lightwell will fund important work. Megalodon already shipped.

    → Week #22/2026 also covers: #ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  13. 🕵🏻‍♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.

    #Megalodon backdoored 5,500 #GitHub repositories in six hours. Not six days — six hours. Malicious commits silently replacing CI/CD workflows, hoovering tokens, cloud credentials, SSH keys, and environment variables before most of the affected projects had processed a single alert. The same week, #IBM and #RedHat announced a $5 billion commitment, called Project Lightwell, to securing the open source supply chain, #Anthropic's #Mythos model surfaced 23,000 potential vulnerabilities across 1,000 OSS projects, and Apple open-sourced its quantum-resistant crypto stack with formal verification proofs attached. The industry's response to supply chain risk is finally arriving at a scale that looks serious.

    The problem is the math. The response is measured in billions of dollars and multi-year programs. The attack is measured in hours and automated tooling. Megalodon's six-hour window isn't an anomaly — it's a benchmark. Last week it was TeamPCP and the GitHub cascade. The week before, Laravel Lang and malicious postinstall hooks across 700 repos. The investment in defense is real and necessary, but it's being deployed against a threat that doesn't need a budget cycle to iterate. Project Lightwell will fund important work. Megalodon already shipped.

    → Week #22/2026 also covers: #ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  14. 🕵🏻‍♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.

    #Megalodon backdoored 5,500 #GitHub repositories in six hours. Not six days — six hours. Malicious commits silently replacing CI/CD workflows, hoovering tokens, cloud credentials, SSH keys, and environment variables before most of the affected projects had processed a single alert. The same week, #IBM and #RedHat announced a $5 billion commitment, called Project Lightwell, to securing the open source supply chain, #Anthropic's #Mythos model surfaced 23,000 potential vulnerabilities across 1,000 OSS projects, and Apple open-sourced its quantum-resistant crypto stack with formal verification proofs attached. The industry's response to supply chain risk is finally arriving at a scale that looks serious.

    The problem is the math. The response is measured in billions of dollars and multi-year programs. The attack is measured in hours and automated tooling. Megalodon's six-hour window isn't an anomaly — it's a benchmark. Last week it was TeamPCP and the GitHub cascade. The week before, Laravel Lang and malicious postinstall hooks across 700 repos. The investment in defense is real and necessary, but it's being deployed against a threat that doesn't need a budget cycle to iterate. Project Lightwell will fund important work. Megalodon already shipped.

    → Week #22/2026 also covers: #ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance.

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨 #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  15. #TeamPCP war gestern – Auftritt #Megalodon

    TeamPCP hatte auf GitHub rund 3.800 Repositories kontaminiert. Jetzt kommt Megalodon und vergiftet auf Anhieb 5.561 Repos (Stand 2026-05-22). Damit erleben wir einen weiteren, noch größeren Lieferketten-Angriff als mit TeamPCP. Etliche Fragen sind noch offen, beispielsweise ob ein Zusammenhang zwischen TeamPCP und Megalodon besteht (abgesehen davon, dass beides raffinierte Lieferketten-Angriffe sind). Spoiler: Megalodon scheint eigenständig und unabhängig von TeamPCP zu sein. Weshalb betreffen diese Angriffe uns alle, es werden doch nur Konten und Repos von Entwickler/inne/n korrumpiert?

    Aus zwei Gründen betrifft das uns alle:

    pc-fluesterer.info/wordpress/2

    #Allgemein #Empfehlung #Hintergrund #Warnung #Website #foss #github #npm

  16. #TeamPCP war gestern – Auftritt #Megalodon

    TeamPCP hatte auf GitHub rund 3.800 Repositories kontaminiert. Jetzt kommt Megalodon und vergiftet auf Anhieb 5.561 Repos (Stand 2026-05-22). Damit erleben wir einen weiteren, noch größeren Lieferketten-Angriff als mit TeamPCP. Etliche Fragen sind noch offen, beispielsweise ob ein Zusammenhang zwischen TeamPCP und Megalodon besteht (abgesehen davon, dass beides raffinierte Lieferketten-Angriffe sind). Spoiler: Megalodon scheint eigenständig und unabhängig von TeamPCP zu sein. Weshalb betreffen diese Angriffe uns alle, es werden doch nur Konten und Repos von Entwickler/inne/n korrumpiert?

    Aus zwei Gründen betrifft das uns alle:

    pc-fluesterer.info/wordpress/2

    #Allgemein #Empfehlung #Hintergrund #Warnung #Website #foss #github #npm

  17. RE: infosec.exchange/@cyberseckyle

    It should be noted that this "Megalodon" has nothing to do with the #Fediverse API project or the old pink Megalodon Fediverse App.

    "On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets to a C2 server at 216.126.225.129:8443." #Mastodon #MastoAdmin #Megalodon #Github
    stepsecurity.io/blog/megalodon

    Fediverse Project:
    github.com/h3poteto/megalodon

    Old Pink App:github.com/sk22/megalodon

  18. RE: infosec.exchange/@cyberseckyle

    It should be noted that this "Megalodon" has nothing to do with the #Fediverse API project or the old pink Megalodon Fediverse App.

    "On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets to a C2 server at 216.126.225.129:8443." #Mastodon #MastoAdmin #Megalodon #Github
    stepsecurity.io/blog/megalodon

    Fediverse Project:
    github.com/h3poteto/megalodon

    Old Pink App:github.com/sk22/megalodon

  19. Megalodon: 5.561 repository GitHub compromessi in sei ore con workflow CI/CD malevoli

    In sei ore il 18 maggio 2026, la campagna automatizzata Megalodon ha iniettato 5.718 commit malevoli in 5.561 repository GitHub, esfiltrandone credenziali cloud, chiavi SSH e segreti CI/CD verso un C2 esterno. L'operazione, collegata al gruppo TeamPCP, rappresenta uno degli attacchi alla supply chain dello sviluppo software più rapidi mai documentati e ha spinto npm a invalidare migliaia di token di accesso con bypass 2FA.

    insicurezzadigitale.com/megalo

  20. Megalodon: 5.561 repository GitHub compromessi in sei ore con workflow CI/CD malevoli

    In sei ore il 18 maggio 2026, la campagna automatizzata Megalodon ha iniettato 5.718 commit malevoli in 5.561 repository GitHub, esfiltrandone credenziali cloud, chiavi SSH e segreti CI/CD verso un C2 esterno. L'operazione, collegata al gruppo TeamPCP, rappresenta uno degli attacchi alla supply chain dello sviluppo software più rapidi mai documentati e ha spinto npm a invalidare migliaia di token di accesso con bypass 2FA.

    insicurezzadigitale.com/megalo

  21. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

  22. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

    #Megalodon #Malware #TileDesk

  23. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

    #Megalodon #Malware #TileDesk

  24. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

    #Megalodon #Malware #TileDesk

  25. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

    #Megalodon #Malware #TileDesk

  26. Can someone clarify how the malware spread?

    So it initially came from and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  27. Can someone clarify how the #Megalodon malware spread?

    So it initially came from #Tiledesk and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  28. Can someone clarify how the #Megalodon malware spread?

    So it initially came from #Tiledesk and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  29. Can someone clarify how the #Megalodon malware spread?

    So it initially came from #Tiledesk and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  30. Can someone clarify how the #Megalodon malware spread?

    So it initially came from #Tiledesk and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  31. GitHub Repos Targeted in 5,500+ Malicious Commits

    A shocking new campaign, dubbed Megalodon, has injected malware into over 5,500 GitHub repositories, putting sensitive credentials and tokens at risk of being stolen. This alarming attack highlights the growing threat of supply chain attacks, with experts warning that this could be just the beginning.

    osintsights.com/github-repos-t

    #SupplyChain #MaliciousCommits #CredentialstealingMalware #CicdPipeline #Megalodon

  32. 📢⚠️ Hackers targeted more than 5,500 #GitHub repositories in a massive “Megalodon” cyberattack that spread fake code updates and hidden backdoors in just 6 hours. Researchers warn developers to review recent changes and rotate cloud credentials immediately.

    Read: hackread.com/github-repositori

    #CyberSecurity #Megalodon #Hacking #DataBreach #Developers

  33. 📢⚠️ Hackers targeted more than 5,500 #GitHub repositories in a massive “Megalodon” cyberattack that spread fake code updates and hidden backdoors in just 6 hours. Researchers warn developers to review recent changes and rotate cloud credentials immediately.

    Read: hackread.com/github-repositori

    #CyberSecurity #Megalodon #Hacking #DataBreach #Developers

  34. GitHub Megalodon Attack Targets Repos with Malicious CI/CD Workflows

    In a shocking six-hour blitz on May 18, 2026, attackers unleashed a massive supply-chain campaign dubbed "Megalodon," pushing 5,718 malicious commits to 5,561 GitHub repositories. The sneaky assault mimicked routine CI maintenance, using fake author names and convincing commit messages to deceive victims.

    osintsights.com/github-megalod

    #Megalodon #Github #SupplyChain #Cicd #EmergingThreats