Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Just absolutely no regard for security at all.

Just absolutely no regard for security at all.

Scheduled Pinned Locked Moved Uncategorized
13 Posts 10 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mhoye@cosocial.caM mhoye@cosocial.ca

    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

    Link Preview Image
    oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
    oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
    oxyhyxo@mastodon.bsd.cafe
    wrote last edited by
    #2

    @mhoye 😔

    1 Reply Last reply
    0
    • R relay@relay.infosec.exchange shared this topic
    • mhoye@cosocial.caM mhoye@cosocial.ca

      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

      Link Preview Image
      lerxst@az.socialL This user is from outside of this forum
      lerxst@az.socialL This user is from outside of this forum
      lerxst@az.social
      wrote last edited by
      #3

      @mhoye If we didn't learn from the left pad incident, we never will. This is just a new payload for an existing threat vector.

      1 Reply Last reply
      0
      • mhoye@cosocial.caM mhoye@cosocial.ca

        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

        Link Preview Image
        pmc@mastodon.ffcentral.netP This user is from outside of this forum
        pmc@mastodon.ffcentral.netP This user is from outside of this forum
        pmc@mastodon.ffcentral.net
        wrote last edited by
        #4

        @mhoye @cwebber Why the hell does a triage bot have the NPM token in the first place

        1 Reply Last reply
        0
        • mhoye@cosocial.caM mhoye@cosocial.ca

          Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

          Link Preview Image
          delta_vee@mstdn.caD This user is from outside of this forum
          delta_vee@mstdn.caD This user is from outside of this forum
          delta_vee@mstdn.ca
          wrote last edited by
          #5

          @mhoye This is the real "we're cooked"

          1 Reply Last reply
          0
          • mhoye@cosocial.caM mhoye@cosocial.ca

            Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

            Link Preview Image
            hennell@phpc.socialH This user is from outside of this forum
            hennell@phpc.socialH This user is from outside of this forum
            hennell@phpc.social
            wrote last edited by
            #6

            @mhoye While the whole situation from AI injection down to 'packages can postinstall global packages' is a series of bad to insane decisions, the only thing I really don't understand is ... why install openclaw on machines? Was this trying to achieve something or just show it was possible?

            1 Reply Last reply
            0
            • mhoye@cosocial.caM mhoye@cosocial.ca

              Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

              Link Preview Image
              endorama@hachyderm.ioE This user is from outside of this forum
              endorama@hachyderm.ioE This user is from outside of this forum
              endorama@hachyderm.io
              wrote last edited by
              #7

              @mhoye could you share the source? Thanks in advance

              mhoye@cosocial.caM 1 Reply Last reply
              0
              • mhoye@cosocial.caM mhoye@cosocial.ca

                Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                Link Preview Image
                stepheneb@ruby.socialS This user is from outside of this forum
                stepheneb@ruby.socialS This user is from outside of this forum
                stepheneb@ruby.social
                wrote last edited by
                #8

                @mhoye

                “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                Link Preview Image
                Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

                GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

                favicon

                GitHub (github.com)

                stepheneb@ruby.socialS 1 Reply Last reply
                0
                • stepheneb@ruby.socialS stepheneb@ruby.social

                  @mhoye

                  “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                  A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                  Link Preview Image
                  Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

                  GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

                  favicon

                  GitHub (github.com)

                  stepheneb@ruby.socialS This user is from outside of this forum
                  stepheneb@ruby.socialS This user is from outside of this forum
                  stepheneb@ruby.social
                  wrote last edited by
                  #9

                  @mhoye

                  I didn’t know about using “OpenID Connect (OIDC) to authenticate GitHub Actions” and wonder how many surfaces it closes and whether it opens new surfaces?

                  Link Preview Image
                  OpenID Connect reference - GitHub Docs

                  Find information about using OpenID Connect (OIDC) to authenticate GitHub Actions workflows with cloud providers.

                  favicon

                  GitHub Docs (docs.github.com)

                  1 Reply Last reply
                  0
                  • mhoye@cosocial.caM mhoye@cosocial.ca

                    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                    Link Preview Image
                    mhoye@cosocial.caM This user is from outside of this forum
                    mhoye@cosocial.caM This user is from outside of this forum
                    mhoye@cosocial.ca
                    wrote last edited by
                    #10

                    Links:

                    Link Preview Image
                    A GitHub Issue Title Compromised 4,000 Developer Machines

                    A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

                    favicon

                    (grith.ai)

                    Link Preview Image
                    Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

                    GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

                    favicon

                    GitHub (github.com)

                    1 Reply Last reply
                    0
                    • endorama@hachyderm.ioE endorama@hachyderm.io

                      @mhoye could you share the source? Thanks in advance

                      mhoye@cosocial.caM This user is from outside of this forum
                      mhoye@cosocial.caM This user is from outside of this forum
                      mhoye@cosocial.ca
                      wrote last edited by
                      #11

                      @endorama

                      Link Preview Image
                      A GitHub Issue Title Compromised 4,000 Developer Machines

                      A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

                      favicon

                      (grith.ai)

                      1 Reply Last reply
                      0
                      • mhoye@cosocial.caM mhoye@cosocial.ca

                        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                        Link Preview Image
                        cdamian@rls.socialC This user is from outside of this forum
                        cdamian@rls.socialC This user is from outside of this forum
                        cdamian@rls.social
                        wrote last edited by
                        #12

                        @mhoye
                        Could you provide a source URL to this?

                        1 Reply Last reply
                        0
                        • mhoye@cosocial.caM mhoye@cosocial.ca

                          Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                          Link Preview Image
                          pseudonym@mastodon.onlineP This user is from outside of this forum
                          pseudonym@mastodon.onlineP This user is from outside of this forum
                          pseudonym@mastodon.online
                          wrote last edited by
                          #13

                          @mhoye

                          #infosec

                          Install attack surface as a service.

                          IASaaS

                          No, swap that...

                          Attack Interface Surface as a Service

                          AISaaS

                          1 Reply Last reply
                          0
                          • R relay@relay.an.exchange shared this topic
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • World
                          • Users
                          • Groups