Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cyberbender
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
1.
▲
Repo-Jacking Anthropic's Claude Community Plugins (and the SHAs That Saved Them)
(johnstawinski.com)
2 points
by
cyberbender
3mo ago
|
0 comments
2.
▲
Unauthorized Prompt Injection to RCE in Anthropic's Claude Code Action
(johnstawinski.com)
1 points
by
cyberbender
7mo ago
|
0 comments
3.
▲
Introducing: GitHub Device Code Phishing
(praetorian.com)
4 points
by
cyberbender
1y ago
|
0 comments
4.
▲
Node.js Repository Jenkins Code Execution and Potential Supply Chain Attack
(praetorian.com)
3 points
by
cyberbender
1y ago
|
1 comments
5.
▲
Public secrets exposure leads to supply chain attack on GitHub CodeQL
(praetorian.com)
297 points
by
cyberbender
1y ago
|
61 comments
6.
▲
Breaching Microsoft via DeepSpeed GitHub Repository
(johnstawinski.com)
6 points
by
cyberbender
2y ago
|
3 comments
7.
▲
by
cyberbender
2y ago
This is great; the less long-lived credentials the better! Now developers just need to make sure they secure their code at the pipeline level. Pipeline compromise = package compromise.
8.
▲
by
cyberbender
2y ago
Wow, I remember attempting to do this in University...glad someone much smarter than me figured it out :)
9.
▲
by
cyberbender
2y ago
I've seen this firsthand...I think it is less of an issue at smaller companies where taking initiative and leaning into their intelligence is less politically restricted. At large organizations, often it requires too much energy for th
10.
▲
by
cyberbender
2y ago
Does anyone know if Amazon can push patches down to these devices? Or are they forever vulnerable once the issue is discovered?