Security

I just watched a video about this yesterday. At the start of the video I immediately thought "It's Russia".

1 replies

17 bugs in 10 weeks from AI security scanning

9d 13h ago by programming.dev/u/codeinabox in security@programming.dev from lalitm.com
-102

Why Hardened Images are Suddenly Everywhere

15d 13h ago by programming.dev/u/codeinabox in security@programming.dev from redmonk.com
323

Typosquatted npm packages used to steal cloud and CI/CD secrets

19d 19h ago by programming.dev/u/codeinabox in security@programming.dev from www.microsoft.com
604

The approval prompt is lying: a critical coding agent security flaw

20d 19h ago by programming.dev/u/codeinabox in security@programming.dev from adversa.ai
405

GitHub Actions Cache Poisoning is eating open source

1mon 1d ago by programming.dev/u/codeinabox in security@programming.dev from neciudan.dev
2876

Mythos finds a curl vulnerability

1mon 7d ago by programming.dev/u/codeinabox in security@programming.dev from daniel.haxx.se
1117

Why “Trusted Publishing” Can’t Save Us from Social Engineering

1mon 11d ago by programming.dev/u/codeinabox in security@programming.dev from adventures.nodeland.dev
408

Your Container Is Not a Sandbox

1mon 12d ago by programming.dev/u/codeinabox in security@programming.dev from emirb.github.io
2879

Arbitrary code execution and Claude Code CLI: How Claude executed code before you click 'trust'

1mon 18d ago by programming.dev/u/codeinabox in security@programming.dev from www.sonarsource.com
8110

At Machine Speed

1mon 19d ago by programming.dev/u/codeinabox in security@programming.dev from matthiasott.com
5011

Open source package with 1 million monthly downloads stole user credentials

1mon 21d ago by discuss.tchncs.de/u/schnurrito in security@programming.dev from arstechnica.com
20112

Npm Slop & Wonky Software Supply Chains

1mon 22d ago by programming.dev/u/codeinabox in security@programming.dev from simonramstedt.com
0013

Mythos Mystery in Mozilla Numbers: How 22 Vulns Became 271 or Maybe 3 in April

1mon 24d ago by programming.dev/u/codeinabox in security@programming.dev from www.flyingpenguin.com
1014

The Vercel breach started at a tool nobody was watching

1mon 27d ago by programming.dev/u/codeinabox in security@programming.dev from siddhantkhare.com
6115

pompelmi – ClamAV antivirus scanning for Node.js, zero dependencies

1mon 27d ago by programming.dev/u/justsouichi in security@programming.dev from github.com
1016

Anthropic secretly installs spyware when you install Claude Desktop

1mon 28d ago by programming.dev/u/codeinabox in security@programming.dev from www.thatprivacyguy.com
1781817

We Reproduced Anthropic's Mythos Findings With Public Models

2mon 1d ago by programming.dev/u/codeinabox in security@programming.dev from blog.vidocsecurity.com
11018

The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic

2mon 2d ago by programming.dev/u/codeinabox in security@programming.dev from www.flyingpenguin.com
14119

Cybersecurity Looks Like Proof of Work Now

2mon 3d ago by programming.dev/u/codeinabox in security@programming.dev from www.dbreunig.com
2020

Dependency cooldowns turn you into a free-rider

2mon 3d ago by programming.dev/u/codeinabox in security@programming.dev from calpaterson.com
6021

AI “Watershed Moment” or expensive pen tester? The AISI Mythos Data

2mon 4d ago by programming.dev/u/codeinabox in security@programming.dev from blog.robbowley.net
2022

Our evaluation of Claude Mythos Preview’s cyber capabilities

2mon 4d ago by programming.dev/u/codeinabox in security@programming.dev from www.aisi.gov.uk
4123

No one owes you supply-chain security

2mon 6d ago by programming.dev/u/codeinabox in security@programming.dev from purplesyringa.moe
13324

Package Security Problems for AI Agents

2mon 9d ago by programming.dev/u/codeinabox in security@programming.dev from nesbitt.io
2026

Assessing Claude Mythos Preview’s cybersecurity capabilities

2mon 10d ago by programming.dev/u/codeinabox in security@programming.dev from red.anthropic.com
4127

Minimum Release Age is an Underrated Supply Chain Defense

2mon 10d ago by programming.dev/u/codeinabox in security@programming.dev from daniakash.com
29628

Bounty Available (>$2,000) for QubesOS BusKill package

2mon 11d ago by lemdro.id/u/buskill in security@programming.dev from www.buskill.in
0029

OpenClaw gives users yet another reason to be freaked out about security

2mon 14d ago by programming.dev/u/codeinabox in security@programming.dev from arstechnica.com
20030

Stop Committing Your Secrets (You Know Who You Are)

2mon 14d ago by programming.dev/u/codeinabox in security@programming.dev from jfmaes.me
8031

Don’t let A.I. read your .env files

2mon 15d ago by programming.dev/u/codeinabox in security@programming.dev from filiphric.com
14432

AfterPack: Claude Code's Source Didn't Leak. It Was Already Public for Years.

2mon 17d ago by lemmy.world/u/artwork in security@programming.dev
8033

Supply Chain Attack on Axios Pulls Malicious Dependency from npm

2mon 18d ago by programming.dev/u/codeinabox in security@programming.dev from socket.dev
4034

Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild

2mon 22d ago by lemmy.world/u/Innerworld in security@programming.dev from www.wired.com
7036

Iranian-linked hackers claimed responsibility for the breach of FBI Direct Kash Patel’s personal email account

2mon 22d ago by lemmy.world/u/Innerworld in security@programming.dev from www.reuters.com
12037

Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets

2mon 22d ago by programming.dev/u/Kissaki in security@programming.dev from socket.dev
6038

Compromised telnyx on PyPI: WAV Steganography and Credential Theft

2mon 22d ago by programming.dev/u/Kissaki in security@programming.dev from safedep.io
3039

Hackers have exposed more than 8.3 million supposedly confidential reports to tip lines like Crime Stoppers

2mon 22d ago by lemmy.world/u/Innerworld in security@programming.dev from san.com
3040

TeamPCP deploys CanisterWorm on NPM following Trivy compromise

2mon 23d ago by programming.dev/u/codeinabox in security@programming.dev from www.aikido.dev
2041

Thousands of websites are accidentally broadcasting sensitive data

2mon 23d ago by lemmy.world/u/Innerworld in security@programming.dev from techxplore.com
6242

Delve - Fake Compliance as a Service

2mon 25d ago by programming.dev/u/Kissaki in security@programming.dev from deepdelver.substack.com
8243

DoJ has taken down botnets behind the largest-ever DDoS attack

2mon 29d ago by lemmy.world/u/Innerworld in security@programming.dev from www.wired.com
2045

Countries with Most Personal Records Leaked in Data Breaches (2004-2025)

3mon 10d ago by lemmy.world/u/Innerworld in security@programming.dev from www.voronoiapp.com
39146