Subscribe For The Latest Edition

Major OpenSSH Vulnerability, TeamViewer Hacked By Russian APT, Google Ads Serve Malware, and more

Want to sponsor my next edition and reach over 1,000 cybersecurity professionals?

More Stories

Polyfill Supply Chain Attack Takes A Weird Twist

In last week’s edition we talked about how Polyfill’s JavaScript library was backdoored, putting over 100,000 websites at risk. Well, since then, Polyfill has responded, and their response was pretty downright unhinged. The company went on a long Twitter tirade, doing everything from accusing the media of baseless slander, to claiming Cloudflare mirroring Polyfill’s CDN with a non-malicious version of their library is anti-competitive.


Polyfill also encourages customers to move over to their new web address, as their previous one was suspended for distributing malware. The company then went on to claim they’re committing to putting Cloudflare out of business by starting a better version of their product.


Notably absent from any of their statements was any sort of explanation as to how their library ended up distributing malicious code, or what they’re doing to remedy the situation.


While I generally favor the phrase “never attribute to malice that which can easily be explained by incompetence”, I’m going to make an exception here. Polyfill’s completely absurd reaction, coupled with their total lack of accountability, makes me think that they’re either complicit or at best displaying weapons grade incompetence.



Rabbit R1 AI-Powered Personal Assistant Hacked

Rabbitude (a group focused on jailbreaking the Rabbit R1) came into possession of several critical API keys while reverse engineering the device. These keys allowed them to access logs of every response sent from the assistant to its user, as well as potentially brick all devices. What’s worse, they claim to have informed the company, which allegedly acknowledged the issue, yet chose to ignore it.


Only after Rabbitude went public with their findings did Rabbit finally release a disclosure and revoke (some of) the API keys. However, Rabbitude found that they were still able to send emails from Rabbit’s internal email server, which the CEO allegedly tried to downplay, imply the emails could have been spoofed.


Overall, Rabbit’s handling of the security breach leaves a lot to be desired, but it’s unfortunately not even the worst one today.

Vulnerability Watch

Thank you for subscribing!

If you have any suggestions for sections or stories you'd like to see in the next edition, please don't hesitate to reach out!