<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.3.4">Jekyll</generator><link href="https://aydinnyunus.github.io/feed.xml" rel="self" type="application/atom+xml" /><link href="https://aydinnyunus.github.io/" rel="alternate" type="text/html" /><updated>2026-08-12T16:48:54+00:00</updated><id>https://aydinnyunus.github.io/feed.xml</id><title type="html">Yunus Aydın Blog</title><subtitle>Supply-chain security, CVE deep-dives, and open-source vulnerability research. npm malware analysis, browser extension reversing, GitHub Archive secret scanning, and responsible disclosure write-ups.</subtitle><author><name>Yunus Aydın</name></author><entry xml:lang="tr"><title type="html">Worklo: Sahte Startup, Gerçek Malware</title><link href="https://aydinnyunus.github.io/2026/08/06/worklo-fake-job-npm-supply-chain-malware-tr/" rel="alternate" type="text/html" title="Worklo: Sahte Startup, Gerçek Malware" /><published>2026-08-06T00:00:00+00:00</published><updated>2026-08-06T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/08/06/worklo-fake-job-npm-supply-chain-malware-tr</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[Worklo adlı sahte bir startup, LinkedIn üzerinden geliştirici hedefleyerek take-home assignment içine gizlenmiş npm supply chain malware dağıttı. Private scoped package ve embedded auth token ile çalışan RCE dropper analizi.]]></summary></entry><entry xml:lang="en"><title type="html">Worklo: Fake Startup, Real Malware in the Take-Home Assignment</title><link href="https://aydinnyunus.github.io/2026/08/06/worklo-fake-job-npm-supply-chain-malware/" rel="alternate" type="text/html" title="Worklo: Fake Startup, Real Malware in the Take-Home Assignment" /><published>2026-08-06T00:00:00+00:00</published><updated>2026-08-06T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/08/06/worklo-fake-job-npm-supply-chain-malware</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[A fake startup called Worklo used LinkedIn recruiters, a polished website, and a rigged take-home assignment to deliver npm supply chain malware via a private scoped package with an embedded auth token.]]></summary></entry><entry xml:lang="tr"><title type="html">ModHeader: Browsing Geçmişini Sızdıran Chrome Eklentisi Analizi</title><link href="https://aydinnyunus.github.io/2026/07/12/modheader-data-exfiltration-stanfordstudies-tr/" rel="alternate" type="text/html" title="ModHeader: Browsing Geçmişini Sızdıran Chrome Eklentisi Analizi" /><published>2026-07-12T00:00:00+00:00</published><updated>2026-07-12T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/07/12/modheader-data-exfiltration-stanfordstudies-tr</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[ModHeader Chrome eklentisi (1.6M kullanıcı) AES-GCM ile şifreleyip tüm gezinme geçmişini api.stanfordstudies.com'a gönderiyor. Full reverse engineering analizi.]]></summary></entry><entry xml:lang="en"><title type="html">ModHeader: Covert Data Exfiltration to api.stanfordstudies.com</title><link href="https://aydinnyunus.github.io/2026/07/12/modheader-data-exfiltration-stanfordstudies/" rel="alternate" type="text/html" title="ModHeader: Covert Data Exfiltration to api.stanfordstudies.com" /><published>2026-07-12T00:00:00+00:00</published><updated>2026-07-12T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/07/12/modheader-data-exfiltration-stanfordstudies</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[ModHeader browser extension silently exfiltrates browsing history to api.stanfordstudies.com using AES-GCM encrypted IndexedDB. Full reverse engineering analysis.]]></summary></entry><entry xml:lang="tr"><title type="html">GitHub Archive’da AI ile 3.800+ Sızdırılmış Secret Nasıl Buldum</title><link href="https://aydinnyunus.github.io/2026/06/30/hunting-leaked-secrets-on-github-archive-tr/" rel="alternate" type="text/html" title="GitHub Archive’da AI ile 3.800+ Sızdırılmış Secret Nasıl Buldum" /><published>2026-06-30T00:00:00+00:00</published><updated>2026-06-30T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/06/30/hunting-leaked-secrets-on-github-archive-tr</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[Microsoft, Google, Red Hat canlı credential sızdırdı. AI pipeline ile 1.443 repo'da 3.830+ secret'ı saldırganlardan önce bulan sistemin analizi.]]></summary></entry><entry xml:lang="en"><title type="html">How I Found 3,800+ Leaked Secrets on GitHub Archive Using AI</title><link href="https://aydinnyunus.github.io/2026/06/30/hunting-leaked-secrets-on-github-archive/" rel="alternate" type="text/html" title="How I Found 3,800+ Leaked Secrets on GitHub Archive Using AI" /><published>2026-06-30T00:00:00+00:00</published><updated>2026-06-30T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/06/30/hunting-leaked-secrets-on-github-archive</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[Microsoft, Google, Red Hat shipped live credentials to public GitHub. An AI pipeline found 3,830+ verified secrets across 1,443 repos before attackers.]]></summary></entry><entry xml:lang="tr"><title type="html">NPM Tedarik Zinciri: Sahte İş Teklifiyle Gelen Info-Stealer</title><link href="https://aydinnyunus.github.io/2026/06/22/fake-job-offer-npm-supply-chain-malware-foxtopia-tr/" rel="alternate" type="text/html" title="NPM Tedarik Zinciri: Sahte İş Teklifiyle Gelen Info-Stealer" /><published>2026-06-22T00:00:00+00:00</published><updated>2026-06-22T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/06/22/fake-job-offer-npm-supply-chain-malware-foxtopia-tr</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[Typosquat npm paketi (pretie_x1) sahte iş teklifiyle dağıtılıyor. AES şifreli info-stealer tarayıcı şifreleri, kripto cüzdanları ve SSH anahtarlarını hedefliyor.]]></summary></entry><entry xml:lang="en"><title type="html">NPM Supply Chain Attack: Fake Job Offer Drops Info-Stealer</title><link href="https://aydinnyunus.github.io/2026/06/22/fake-job-offer-npm-supply-chain-malware-foxtopia/" rel="alternate" type="text/html" title="NPM Supply Chain Attack: Fake Job Offer Drops Info-Stealer" /><published>2026-06-22T00:00:00+00:00</published><updated>2026-06-22T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/06/22/fake-job-offer-npm-supply-chain-malware-foxtopia</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[Typosquatted npm package (pretie_x1) delivered via fake job offer drops AES-encrypted info-stealer for browser credentials, crypto wallets, and SSH keys.]]></summary></entry><entry xml:lang="tr"><title type="html">Odysseus: AI Embedding Endpoint’inde Broken Access Control + SSRF (CVE-2026-70619, CVE-2026-70620)</title><link href="https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover-tr/" rel="alternate" type="text/html" title="Odysseus: AI Embedding Endpoint’inde Broken Access Control + SSRF (CVE-2026-70619, CVE-2026-70620)" /><published>2026-06-16T00:00:00+00:00</published><updated>2026-06-16T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover-tr</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[Odysseus CVE-2026-70619/CVE-2026-70620: embedding endpoint'inde broken access control. Admin kontrolü olmayan API ile embedding URL ele geçirme ve tüm chat/RAG/vault verisini sızdırma.]]></summary></entry><entry xml:lang="en"><title type="html">Odysseus: Broken Access Control + SSRF in AI Embedding Endpoint (CVE-2026-70619, CVE-2026-70620)</title><link href="https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover/" rel="alternate" type="text/html" title="Odysseus: Broken Access Control + SSRF in AI Embedding Endpoint (CVE-2026-70619, CVE-2026-70620)" /><published>2026-06-16T00:00:00+00:00</published><updated>2026-06-16T00:00:00+00:00</updated><id>https://aydinnyunus.github.io/2026/06/16/odysseus-embedding-endpoint-takeover</id><author><name>Yunus Aydın</name></author><summary type="html"><![CDATA[Odysseus CVE-2026-70619/CVE-2026-70620: broken access control + SSRF. POST /api/embeddings/endpoint has no admin check. Hijack embedding URL for SSRF and exfiltration of chat, RAG and vault data.]]></summary></entry></feed>