Sabitlenmiş Tweet
Brian Clark
6.5K posts

Brian Clark
@_clarkio
Developer Advocate @Snyksec | Prev @Microsoft @Disney | Web dev and app sec things. Here for community, fun and learning. Not for numbers or influencing you.
More here 👉 Katılım Ocak 2014
1.1K Takip Edilen6.1K Takipçiler

@LawrenceDCodes @tdesseyn I’m with you. If we’re talking strictly offline I might tinker but still wouldn’t give it full autonomy
English

@tdesseyn hard pass for me, no way. no thanks absolutely not under no conditions never. But have fun!
English
Brian Clark retweetledi

Your first instinct after getting hit by the TanStack npm attack is to revoke your GitHub token.
Don't.
The malware polls GitHub every 60 seconds. Gets a 401? It runs rm -rf ~/
Here's the right remediation order before you touch a single credential. youtu.be/YrwM2EFYrUY

YouTube
English
Brian Clark retweetledi

1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
English
Brian Clark retweetledi

A government contractor just leaked a ton of sensitive info including admin passwords for CISA's AWS GovCloud accounts - all to a public GitHub repo.
CISA says they "hold our team members to the highest standards of integrity and operational awareness"
Followed by evidence of them turning off basic GitHub defaults that would protect from publishing secrets. And dictionary passwords that were the name of the service + the year.



English
Brian Clark retweetledi
Brian Clark retweetledi

We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
English

@mattjay @tuckner @SocketSecurity No, use a PreToolUse hook, intercept all npm* commands and redirect to sfw npm. Most agent harnesses support hooks these days. Just ask claude to add the hook for you. #what-hooks-can-enforce" target="_blank" rel="nofollow noopener">agentpatterns.ai/verification/h…
English

@mattjay @tuckner @SocketSecurity Hooks are deterministic and make sure what you want to happen, happens
English

The timing of this is perfect. I just had a scenario where having learned something on my own helped me catch a bad suggestion by AI...
Addy Osmani@addyosmani
English

@wesbos I was thinking maybe if it got to a solution faster it might be less expensive
English

Just realized I ran all of this with sonnet 4.6
Wes Bos@wesbos
Burned $91.34 with Claude Code /goal in 3.5 hours Unreal, It was able to reverse engineer it!
English

More and more companies are deploying AI-generated code into production. Much of that code contains vulnerabilities. Making traditional AppSec struggle to keep up.
@snyksec + @AnthropicAI's Claude = security at AI speed
👇
snyk.io/news/snyk-embe…
English
Brian Clark retweetledi

Looking forward to chatting with @_clarkio today! Happening in 5 hours. Come hang with us!
youtube.com/live/nt8KvxQiG…

YouTube
English

@liran_tal I'm thinking about the monthly/annual subscriptions changing for them all. Do you think they'll move everything to usage based billing vs. subs?
English

Any guesses on when the same happens at Anthropic, OpenAI, Cursor?
I think it's gonna be in the next 2-3 months.
github.blog/news-insights/…
English





