mastodon.bida.im is part of the decentralized social network powered by Mastodon.
Un'istanza mastodon antifascista. autogestita, italofona con base a Bologna. Rispettosa di privacy e anonimato.

Server stats:

901
active users

Learn more

#java

35 posts22 participants5 posts today

Threat actors misuse Node.js to deliver malware and other malicious payloads

Since October 2024, threat actors have been leveraging Node.js to deliver malware and payloads for information theft and data exfiltration. A recent malvertising campaign uses cryptocurrency trading themes to lure users into downloading malicious installers. The attack chain includes initial access, persistence, defense evasion, data collection, and payload delivery. The malware gathers system information, sets up scheduled tasks, and uses PowerShell for various malicious activities. Another emerging technique involves inline JavaScript execution through Node.js. Recommendations include educating users, monitoring Node.js execution, enforcing PowerShell logging, and implementing endpoint protection.

Pulse ID: 67fec5ac1e94a608250d9aa2
Pulse Link: otx.alienvault.com/pulse/67fec
Pulse Author: AlienVault
Created: 2025-04-15 20:46:36

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

First ever poll ! Without context, are your DTOs (data transfer objects) read only ?

Be it through Python frozen dataclasses, Java lombok Value, or your preferred language feature to make something unmodifiable.

Please boost for reach ! Poll will be open for 3 days.

The level of overengineering in the #java industry is mind-blowing. Never write 10 lines of plain java code when you can do the same by importing 20 libraries and frameworks, writing two pages of obscure json or yaml configuration, get 10% of the performance and 100x the binary size, completely lose control of what your code is doing, and of your memory footprint, but hey it's all dynamic now and you didn't have to write those 10 lines !

In der kommenden Ausgabe des Java Magazins wird mal wieder ein Artikel von mir vertreten sein, dieses mal über Operaton, was es tut und warum wir den Camunda 7 CE Fork durchgeführt haben. Wie man es von mir kennt, natürlich mit dezenter und leiser Überschrift "Camunda 7 ist tot, lang lebe Operaton!" Eine kleine Preview gibt es schon bei entwickler.de.

entwickler.de/open-source/camu

entwickler.de · Camunda 7 ist tot, lang lebe Operaton!Camunda 7 läuft 2025 aus – mit Operaton formiert sich eine Open-Source-Alternative, da Camunda 8 für viele Projekte keine passende Lösung darstellt!

Ich grübel ja über eine #JUG Tour nach… So ernsthaft mal mit dem Rad durch Deutschland und anbieten, positiv darüber zu ranten, warum mir #Java Skripte, #Python HTML + JavaScript ohne Framework-Gescheiß und eine echt coole Datenbank im letzten den Glauben an Software-Engineering ohne AI und Nippes erhalten haben… Würd sich das jemand anhören wollen?

@paul for #java dev I’d absolutely go for the M4 Max one. Except I’m still blissfully pleased with the M2 Max studio I got from the refurbished store in late 2023, and not even feeling the slightest itch to upgrade yet. (Which was part of the point of course). It seems the M3 Ultra model is only serving some very specific use cases