Imagine shipping your company's entire source code to the public. No breach, no hacker. Just one missing file. That's what happened on March 31, 2026, when Claude Code version 2.1.88 went out to npm with a 59.8 MB source map. 512,000 lines of readable TypeScript. Within hours, it was forked over 41,500 times. The cause: no .npmignore file and no "files" whitelist in package.json. So npm shipped everything. "Plain developer error." Which is exactly why it matters. It can happen to anyone. Profero question: when did someone last check what your published packages actually contain? 👀 How to check if you're exposed is in the first comment>>>
1
1
4
198
🕯️
2
4
119
Your production servers are suddenly running a default, insecure config. It looks exactly like an attacker slipped something in. IR protocol triggered. The "attacker"? A developer's AI coding assistant. A developer hit a nasty merge conflict and ran Claude Code with --dangerously-skip-permissions, asking it to "automate the merge and start over." It did. It also reset the server config to its default template. The reviewer saw "All checks passed" and approved. The kicker: that flag came from a viral "10x your coding with AI" video. Question: Who in your org can hand an AI assistant admin rights today, without asking anyone? 👀 Full write-up in the first comment>>>
2
1
2
296
Imagine patching a critical zero-day the same day it drops. You feel great. Except the attacker got in last week, and they're not on that appliance anymore. (Joke on you.) That's what our IR team at Profero saw in multiple Ivanti EPMM cases in 2025 (CVE-2025-4427 and CVE-2025-4428). In several engagements, attackers had already moved laterally and set up persistence before the appliance was isolated. Patching closes the door. It doesn't tell you who already walked through it. Honest question: after you patch an edge device, do you hunt for what's already inside, or move on to the next fire? Our live forensic collection guide is in the first comment>>>
1
1
141
Sunday throwback. In 2023, a large organization called us after a "new" group called DarkBit encrypted its endpoints and ESXi servers. The attackers ignored every attempt to talk and ran a media campaign instead. Their goal was chaos, not money. So there was no negotiation. Our team broke their crypto instead and recovered the data with a mix of file system walking and brute-forcing. Our favorite lesson from that case: encrypted files are not always the end of the story. Attackers make mistakes, and if the data matters, it's worth checking their work. Also: if it works, it's not stupid. The full technical breakdown is in the first comment.>>>
1
1
3
298
Weekend poll for the security folks 🗳️ Monday morning after a quiet weekend. What do you check first? Failed and unusual logins New admin accounts EDR alerts Coffee first, then we'll see
3
1
3
187
Imagine it's 7:43 AM on a Monday. Your CEO's assistant walks in with an envelope marked "TIME SENSITIVE." Inside: a letter from the BianLian ransomware group. $5 million in Bitcoin within 10 days, or your customer data goes to the media. The board gets called. The IR team gets activated. That's a real case our IR team at Profero worked on. Within hours, we confirmed there was no breach. The whole thing was fiction, part of a wider impersonation campaign. No firewall, email filter, or EDR will ever catch a letter. Honest question: if a letter like this hit your CEO's desk tomorrow, who would they call first? 👀 Full story in the first comment>>>
1
1
1
127
It's Cybersecurity Awareness Month. Your employees will get a phishing quiz. A poster about strong passwords. Maybe a mug. And that's fine. But here's the thing nobody puts on a poster: someone will click eventually. A breach isn't a question of if. The real question is what happens in the hour after that click. Who gets the alert? Who makes the call? Who's awake? So, honest question for the security folks: if your company ran an awareness drill for the IR plan instead of the users, how would it go? 👀 Our take on why so many orgs struggle with proactive readiness is in the first comment>>>
1
3
115
The worst time to set up an incident channel is during the incident. Decide your war room now. Have an out-of-band backup. Know who's in the room. At 2 AM, "we'll figure it out" costs you the first hour.
1
2
127
Imagine getting your servers encrypted...with a tool Microsoft ships inside Windows. That's what happened in an incident our IR team at Profero worked on together with Security Joes. The attackers didn't even bother bringing their own ransomware. They used BitLocker. Windows' own drive encryption, turned against its owner. The report is from December 2020, and it still feels scarily relevant. So, honest question for the security folks here: How far down your vendor chain do you actually look? One level? Two? Or is it more of a "we trust them, they trust someone" situation? 👀 Full report (with IOCs and YARA rules) in the first comment 👇
2
2
7
513
The board doesn't want to hear 'we have a retainer.' They want to hear 'we're ready. Are you?
1
3
209
Your most trusted vendor might be an attacker's favorite delivery service.
1
161
MFA is great. Attackers think so too.
1
1
2
283