⤷ Title: Malicious Packages Weaponize OAST for Stealthy Data Exfiltration and Reconnaissance
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Mon, 06 Jan 2025 01:41:00 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #npm #OAST techniques #PyPI #RubyGems
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Mon, 06 Jan 2025 01:41:00 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #npm #OAST techniques #PyPI #RubyGems
Cybersecurity News
Malicious Packages Weaponize OAST for Stealthy Data Exfiltration and Reconnaissance
Uncover the misuse of OAST techniques by threat actors. Learn how ethical security assessments tools are being hijacked for nefarious purposes.
⤷ Title: Alert: Malicious RubyGems Impersonate Fastlane Plugins, Steal CI/CD Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 00:24:29 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD #cybersecurity #Fastlane #malware #RubyGems #Software security #supply chain attack #Telegram #Typosquatting #Vietnam
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 00:24:29 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD #cybersecurity #Fastlane #malware #RubyGems #Software security #supply chain attack #Telegram #Typosquatting #Vietnam
Daily CyberSecurity
Alert: Malicious RubyGems Impersonate Fastlane Plugins, Steal CI/CD Data
Socket uncovers malicious RubyGems impersonating Fastlane plugins, stealing sensitive CI/CD data by rerouting Telegram API calls. Beware of fastlane-plugin-telegram-proxy!
⤷ Title: RubyGems Under Attack: 60 Malicious Packages Found Stealing Credentials from Grey-Hat Marketers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 03:00:37 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Grey_Hat Marketing #Infostealer #malware #Ruby #RubyGems #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 03:00:37 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Grey_Hat Marketing #Infostealer #malware #Ruby #RubyGems #supply chain attack #Typosquatting
Daily CyberSecurity
RubyGems Under Attack: 60 Malicious Packages Found Stealing Credentials from Grey-Hat Marketers
Socket uncovers a long-running supply chain attack on RubyGems. A threat actor published 60 malicious gems stealing credentials from grey-hat marketers.
⤷ Title: Rack Security Update: High-Severity Flaw Bypasses Parameter Limit, Exposing Apps to DoS Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 08:37:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_59830 #Denial of Service #dos #QueryParser #Rack #Ruby #RubyGems #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 08:37:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_59830 #Denial of Service #dos #QueryParser #Rack #Ruby #RubyGems #Web Security
Daily CyberSecurity
Rack Security Update: High-Severity Flaw Bypasses Parameter Limit, Exposing Apps to DoS Attacks
Rack patches CVE-2025-59830 (CVSS 7.5), a flaw where attackers could use semicolon separators to bypass the parameter count limit and trigger DoS attacks.
⤷ Title: Stealth C2: Hackers Abuse Discord Webhooks for Covert Data Exfiltration in npm, PyPI, and RubyGems Supply Chain Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 00:14:16 +0000
════════════════════════
⌗ Tags: #Malware #data exfiltration #Discord #npm #PyPI #RubyGems #Stealth #supply chain attack #Webhook C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 00:14:16 +0000
════════════════════════
⌗ Tags: #Malware #data exfiltration #Discord #npm #PyPI #RubyGems #Stealth #supply chain attack #Webhook C2
Daily CyberSecurity
Stealth C2: Hackers Abuse Discord Webhooks for Covert Data Exfiltration in npm, PyPI, and RubyGems Supply Chain Attacks
Malicious packages across npm, PyPI, and RubyGems are exploiting Discord webhooks as stealthy, resilient C2 endpoints to exfiltrate developer config files and sensitive host data.
⤷ Title: Rate Limiting Your Rails API with Rack::Attack gem
════════════════════════
𐀪 Author: Talha Khalid
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:52:59 GMT
════════════════════════
⌗ Tags: #api_rate_limiting #api_security #ruby_on_rails #web_development #rubygems
════════════════════════
𐀪 Author: Talha Khalid
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:52:59 GMT
════════════════════════
⌗ Tags: #api_rate_limiting #api_security #ruby_on_rails #web_development #rubygems
Medium
Rate Limiting Your Rails API with Rack::Attack gem
Rate limiting is a fundamental aspect of API security and stability. Without it, endpoints are vulnerable to brute force attacks…
⤷ Title: Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
⌗ Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
⌗ Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack
Daily CyberSecurity
Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
Socket uncovers a BufferZoneCorp "sleeper" campaign targeting Ruby and Go. Malicious packages steal SSH keys and subvert CI/CD pipelines. Patch now!
⤷ Title: GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 04:21:32 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #data exfiltration #GemStuffer #infosec #Malware Analysis #ModernGov #Ruby Security #RubyGems #Socket #supply chain attack #UK Council Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 04:21:32 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #data exfiltration #GemStuffer #infosec #Malware Analysis #ModernGov #Ruby Security #RubyGems #Socket #supply chain attack #UK Council Security
Daily CyberSecurity
GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping
GemStuffer exploits RubyGems as an illicit data transport to scrape UK council portals. Discover how this supply chain attack bypasses standard defenses.
⤷ Title: RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 09:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cyber Security News #Infosec #Maciej Mensfeld #Malware 2026 #Mend.io #open source security #Package Manager Security #Ruby on Rails #RubyGems #supply chain attack #TeamPCP
Penetration Testing Tools
RubyGems Under Siege: New Account Registrations Suspended After Massive Malware Incursion
RubyGems has temporarily suspended the registration of new accounts following a pervasive assault on the Ruby ecosystem. According