Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
axsharma
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
axsharma
15d ago
Doesn't require a permissions bypass or a prompt, that's the point. Every agent here ships a workspace trust prompt but the payload fires before it's shown. `--dangerously-skip-permissions` is therefore irrelevant as the perm
2.
▲
A Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, Grok
(manifold.security)
2 points
by
axsharma
15d ago
|
7 comments
3.
▲
ClawHub's 23 plugins squat the official @openclaw and @clawhub scopes
(manifold.security)
1 points
by
axsharma
3mo ago
|
0 comments
4.
▲
30 ClawHub Skills Are Quietly Recruiting Your AI Agent into a Crypto Swarm
(manifold.security)
2 points
by
axsharma
5mo ago
|
0 comments
5.
▲
by
axsharma
1y ago
> "even if they've been a malicious actor the whole time" That is a sound argument, even if integrity of the package was to check out (if npm tracks this internally at all). Better to adopt a PyPI-style approach of tempora
6.
▲
by
axsharma
1y ago
Why not instead remove 'panya' as a maintainer from legitimate packages that were unaffected? No recent or malicious versions of Stylus have been published (which generally is the case during a hijack) and no evidence that any wer
7.
▲
Fake VS Code extension on NPM uses altered ScreenConnect utility as spyware
(sonatype.com)
2 points
by
axsharma
2y ago
|
0 comments
8.
▲
by
axsharma
2y ago
Interesting, blogged about this Feb 5th https://www.sonatype.com/blog/fake-vs-code-extension-on-npm-...
9.
▲
by
axsharma
2y ago
Close, that's more gray with a tint.
10.
▲
Can AI Create a White Painting?
(codyznash.github.io)
5 points
by
axsharma
2y ago
|
5 comments
11.
▲
by
axsharma
3y ago
GOV.UK seems conflicted about it lol "You usually do not need a BRP to open a bank account. Contact the bank to check if you’ll need a BRP or if you can use a different document." https://www.gov.uk/biometric-resid
12.
▲
by
axsharma
3y ago
Good point, rather interesting they state "in all our online journeys," rather than in-person. Anytime I've had to verify identity online for bank account opening, it entailed taking a photo of my ID which then goes through a
13.
▲
by
axsharma
3y ago
You need your passport if you've only got a vignette or in-passport visa sticker. BRP is often accepted, in lieu of driving license for bank account opening. https://www.lloydsbank.com/legal/proof-of-identity.html
14.
▲
by
axsharma
3y ago
While there is minimal or no passport control within the CTA, for example when travelling between UK and Ireland, the expectation is that the passenger is a citizen of a country whose nationals would not normally require a visa to enter eit
15.
▲
by
axsharma
3y ago
The author here. The name eFile(.)com is bound to confuse some readers who may mistake it for IRS' e-file system/API. Probably why the company chose that brand name (SEO or whatever). IRS-authorised software providers (who need to
16.
▲
by
axsharma
4y ago
Probable explanation for the mysterious hacks on Xfinity accounts despite having 2FA enabled: 2FA bypass allegedly circulating privately "A researcher has told BleepingComputer that the attacks are being conducted through credential
17.
▲
by
axsharma
4y ago
Add to it that they reviewed "all recent commits to Okta software repositories." Due diligence or indicative of the threat actor having write access? Many unanswered questions.
18.
▲
by
axsharma
4y ago
Same thought here. The domain appears to be associated with Ningbo Sunning Software, a Chinese vendor and likely a Mediatek partner than anything Android.
19.
▲
NPM 'bin' script confusion can override NPM/node commands
(socket.dev)
4 points
by
axsharma
4y ago
|
0 comments
20.
▲
by
axsharma
4y ago
How long 'til this gets DMCA'd...
21.
▲
by
axsharma
4y ago
Avanan had reported seeing this exploited by hackers back in July. https://www.avanan.com/blog/sending-phishing-emails-from-pay...
22.
▲
by
axsharma
4y ago
This, as others have pointed out via tweets and Tutanota themselves acknowledging the technicality on Reddit, is why I couldn't report on it (we received the blog from them too) and am inclined to believe this is sensationalized. http
23.
▲
by
axsharma
4y ago
The irony, Google/Alphabet uses ABC.xyz.
24.
▲
by
axsharma
4y ago
Very true, the left-pad incident from 2016 may have seemed like a one off occurrence but we see protestware revived this year. 1. colors/faker followed the Log4j debacle and was more about corporations using open source heavily but not
25.
▲
by
axsharma
4y ago
You're welcome! If you look at "A Timeline of SSC Attacks" compiled and periodically updated by us, the trend is getting worse than better. To be blunt, the increased volume of these unwanted packages (whether research PoCs o
26.
▲
by
axsharma
4y ago
Hi there, Ax Sharma here from Sonatype - I've written extensively about our malware/hijacked package findings almost every week now on the company blog. The automated malware detection bots flag anything that looks suspicious on n
27.
▲
Go, Rust 'net' library affected by critical IP address validation vulnerability
(bleepingcomputer.com)
1 points
by
axsharma
5y ago
|
0 comments
28.
▲
GitHub Copilot is ‘unacceptable and unjust,’ says Free Software Foundation
(infoworld.com)
252 points
by
axsharma
5y ago
|
232 comments
29.
▲
Maven Central automatically scans Java projects for vulnerabilities
(central.sonatype.org)
3 points
by
axsharma
5y ago
|
1 comments
30.
▲
by
axsharma
5y ago
"Starting this week, we will be scanning all staged repositories on OSSRH automatically as you’re publishing things to Central"
More ›