Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Just absolutely no regard for security at all.

Just absolutely no regard for security at all.

Scheduled Pinned Locked Moved Uncategorized
13 Posts 10 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mhoye@cosocial.caM This user is from outside of this forum
    mhoye@cosocial.caM This user is from outside of this forum
    mhoye@cosocial.ca
    wrote last edited by
    #1

    Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

    Link Preview Image
    oxyhyxo@mastodon.bsd.cafeO lerxst@az.socialL pmc@mastodon.ffcentral.netP delta_vee@mstdn.caD hennell@phpc.socialH 10 Replies Last reply
    2
    0
    • mhoye@cosocial.caM mhoye@cosocial.ca

      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

      Link Preview Image
      oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
      oxyhyxo@mastodon.bsd.cafeO This user is from outside of this forum
      oxyhyxo@mastodon.bsd.cafe
      wrote last edited by
      #2

      @mhoye 😔

      1 Reply Last reply
      0
      • R relay@relay.infosec.exchange shared this topic
      • mhoye@cosocial.caM mhoye@cosocial.ca

        Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

        Link Preview Image
        lerxst@az.socialL This user is from outside of this forum
        lerxst@az.socialL This user is from outside of this forum
        lerxst@az.social
        wrote last edited by
        #3

        @mhoye If we didn't learn from the left pad incident, we never will. This is just a new payload for an existing threat vector.

        1 Reply Last reply
        0
        • mhoye@cosocial.caM mhoye@cosocial.ca

          Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

          Link Preview Image
          pmc@mastodon.ffcentral.netP This user is from outside of this forum
          pmc@mastodon.ffcentral.netP This user is from outside of this forum
          pmc@mastodon.ffcentral.net
          wrote last edited by
          #4

          @mhoye @cwebber Why the hell does a triage bot have the NPM token in the first place

          1 Reply Last reply
          0
          • mhoye@cosocial.caM mhoye@cosocial.ca

            Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

            Link Preview Image
            delta_vee@mstdn.caD This user is from outside of this forum
            delta_vee@mstdn.caD This user is from outside of this forum
            delta_vee@mstdn.ca
            wrote last edited by
            #5

            @mhoye This is the real "we're cooked"

            1 Reply Last reply
            0
            • mhoye@cosocial.caM mhoye@cosocial.ca

              Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

              Link Preview Image
              hennell@phpc.socialH This user is from outside of this forum
              hennell@phpc.socialH This user is from outside of this forum
              hennell@phpc.social
              wrote last edited by
              #6

              @mhoye While the whole situation from AI injection down to 'packages can postinstall global packages' is a series of bad to insane decisions, the only thing I really don't understand is ... why install openclaw on machines? Was this trying to achieve something or just show it was possible?

              1 Reply Last reply
              0
              • mhoye@cosocial.caM mhoye@cosocial.ca

                Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                Link Preview Image
                endorama@hachyderm.ioE This user is from outside of this forum
                endorama@hachyderm.ioE This user is from outside of this forum
                endorama@hachyderm.io
                wrote last edited by
                #7

                @mhoye could you share the source? Thanks in advance

                mhoye@cosocial.caM 1 Reply Last reply
                0
                • mhoye@cosocial.caM mhoye@cosocial.ca

                  Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                  Link Preview Image
                  stepheneb@ruby.socialS This user is from outside of this forum
                  stepheneb@ruby.socialS This user is from outside of this forum
                  stepheneb@ruby.social
                  wrote last edited by
                  #8

                  @mhoye

                  “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                  A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                  Link Preview Image
                  Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

                  GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

                  favicon

                  GitHub (github.com)

                  stepheneb@ruby.socialS 1 Reply Last reply
                  0
                  • stepheneb@ruby.socialS stepheneb@ruby.social

                    @mhoye

                    “the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release.
                    A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.”

                    Link Preview Image
                    Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

                    GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

                    favicon

                    GitHub (github.com)

                    stepheneb@ruby.socialS This user is from outside of this forum
                    stepheneb@ruby.socialS This user is from outside of this forum
                    stepheneb@ruby.social
                    wrote last edited by
                    #9

                    @mhoye

                    I didn’t know about using “OpenID Connect (OIDC) to authenticate GitHub Actions” and wonder how many surfaces it closes and whether it opens new surfaces?

                    Link Preview Image
                    OpenID Connect reference - GitHub Docs

                    Find information about using OpenID Connect (OIDC) to authenticate GitHub Actions workflows with cloud providers.

                    favicon

                    GitHub Docs (docs.github.com)

                    1 Reply Last reply
                    0
                    • mhoye@cosocial.caM mhoye@cosocial.ca

                      Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                      Link Preview Image
                      mhoye@cosocial.caM This user is from outside of this forum
                      mhoye@cosocial.caM This user is from outside of this forum
                      mhoye@cosocial.ca
                      wrote last edited by
                      #10

                      Links:

                      Link Preview Image
                      A GitHub Issue Title Compromised 4,000 Developer Machines

                      A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

                      favicon

                      (grith.ai)

                      Link Preview Image
                      Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

                      GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

                      favicon

                      GitHub (github.com)

                      1 Reply Last reply
                      0
                      • endorama@hachyderm.ioE endorama@hachyderm.io

                        @mhoye could you share the source? Thanks in advance

                        mhoye@cosocial.caM This user is from outside of this forum
                        mhoye@cosocial.caM This user is from outside of this forum
                        mhoye@cosocial.ca
                        wrote last edited by
                        #11

                        @endorama

                        Link Preview Image
                        A GitHub Issue Title Compromised 4,000 Developer Machines

                        A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

                        favicon

                        (grith.ai)

                        1 Reply Last reply
                        0
                        • mhoye@cosocial.caM mhoye@cosocial.ca

                          Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                          Link Preview Image
                          cdamian@rls.socialC This user is from outside of this forum
                          cdamian@rls.socialC This user is from outside of this forum
                          cdamian@rls.social
                          wrote last edited by
                          #12

                          @mhoye
                          Could you provide a source URL to this?

                          1 Reply Last reply
                          0
                          • mhoye@cosocial.caM mhoye@cosocial.ca

                            Just absolutely no regard for security at all. None. The entire burden of self-protection shifted to humans alone at their endpoints in a system that was foundationally built on trust and trustworthiness.

                            Link Preview Image
                            pseudonym@mastodon.onlineP This user is from outside of this forum
                            pseudonym@mastodon.onlineP This user is from outside of this forum
                            pseudonym@mastodon.online
                            wrote last edited by
                            #13

                            @mhoye

                            #infosec

                            Install attack surface as a service.

                            IASaaS

                            No, swap that...

                            Attack Interface Surface as a Service

                            AISaaS

                            1 Reply Last reply
                            0
                            • R relay@relay.an.exchange shared this topic
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups