Brian Clark

6.5K posts

Brian Clark banner
Brian Clark

Brian Clark

@_clarkio

Developer Advocate @Snyksec | Prev @Microsoft @Disney | Web dev and app sec things. Here for community, fun and learning. Not for numbers or influencing you.

More here 👉 Katılım Ocak 2014
1.1K Takip Edilen6.1K Takipçiler
LawrenceDCodes
LawrenceDCodes@LawrenceDCodes·
@tdesseyn hard pass for me, no way. no thanks absolutely not under no conditions never. But have fun!
English
4
0
8
256
taylor desseyn
taylor desseyn@tdesseyn·
am i the only one that feels this at this point i would gladly give ai all my personal info so i can let it run tasks for my personal life ai is amazing at work but its only getting me 76% of the way there for what i need personally
English
5
0
5
704
Brian Clark retweetledi
Snyk
Snyk@snyksec·
Versions of - laravel-lang/lang - laravel-lang/http-statuses - laravel-lang/attributes - laravel-lang/actions have been published with malicious versions Packagist has unlisted the packages, but if you installed any of them between May 22–23, treat the environment as compromised
Snyk tweet media
English
1
7
12
1.4K
Brian Clark
Brian Clark@_clarkio·
Your first instinct after getting hit by the TanStack npm attack is to revoke your GitHub token. Don't. The malware polls GitHub every 60 seconds. Gets a 401? It runs rm -rf ~/ Here's the right remediation order before you touch a single credential. youtu.be/YrwM2EFYrUY
YouTube video
YouTube
English
0
1
1
387
Brian Clark retweetledi
GitHub
GitHub@github·
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
English
586
3.6K
11.6K
7.4M
Brian Clark retweetledi
Matt Johansen
Matt Johansen@mattjay·
A government contractor just leaked a ton of sensitive info including admin passwords for CISA's AWS GovCloud accounts - all to a public GitHub repo. CISA says they "hold our team members to the highest standards of integrity and operational awareness" Followed by evidence of them turning off basic GitHub defaults that would protect from publishing secrets. And dictionary passwords that were the name of the service + the year.
Matt Johansen tweet mediaMatt Johansen tweet mediaMatt Johansen tweet media
English
8
37
187
18.6K
Brian Clark retweetledi
Sarah Drasner
Sarah Drasner@sarah_edo·
💥 Game changer for Web Development announced at GoogleIO- Modern Web Guidance! It’s expert-vetted skills for web development based on best practices of latest specs and APIs. It ensures your agent/coding harness doesn’t default to older and out of date patterns to build sites.
English
19
93
756
89.9K
Brian Clark retweetledi
GitHub
GitHub@github·
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
English
1.7K
5.4K
25.5K
13.7M
onlyLARP
onlyLARP@onlylarp·
@mattjay @tuckner @SocketSecurity No, use a PreToolUse hook, intercept all npm* commands and redirect to sfw npm. Most agent harnesses support hooks these days. Just ask claude to add the hook for you. #what-hooks-can-enforce" target="_blank" rel="nofollow noopener">agentpatterns.ai/verification/h…
English
4
0
9
1.9K
Matt Johansen
Matt Johansen@mattjay·
Everyone using Claude code and/or Codex - how are you enforcing them to not pull in new/potentially malicious packages from npm or PyPi?
English
172
28
529
134.5K
Brian Clark
Brian Clark@_clarkio·
AI wanted to copy node_modules between two stages in a Dockerfile. One where devDeps are needed and one they're not (production). I called this out and it of course replied with "You're right — I should walk that back."
English
0
0
0
110
Brian Clark
Brian Clark@_clarkio·
@wesbos I was thinking maybe if it got to a solution faster it might be less expensive
English
1
0
4
412
Wes Bos
Wes Bos@wesbos·
@_clarkio it would have been way more expensive with opus
English
1
0
22
1.1K
Brian Clark
Brian Clark@_clarkio·
More and more companies are deploying AI-generated code into production. Much of that code contains vulnerabilities. Making traditional AppSec struggle to keep up. @snyksec + @AnthropicAI's Claude = security at AI speed 👇 snyk.io/news/snyk-embe…
English
0
1
2
472
Brian Clark
Brian Clark@_clarkio·
@liran_tal I'm thinking about the monthly/annual subscriptions changing for them all. Do you think they'll move everything to usage based billing vs. subs?
English
1
0
0
21
Liran Tal
Liran Tal@liran_tal·
@_clarkio Uhmmm, isn't the API per 1M token already the usage based pricing? I think GitHub is likely going to have to figure out pricing or some sort of limits around the GitHub core product (PRs, GitHub Actions etc)
English
1
0
0
89