Live data from Hacker News

Viewing profile — kurmiashish

kurmiashish

HN member
Joined
Thu, Sep 24, 2020, 6:05 AM UTC
HN karma
375
Public activity
19 items

About kurmiashish

No profile information was provided.

Recent public activity

  1. comment
    Comment #48452411

    An attacker hijacked a co-founder's GitHub account for gpt-pilot, a 33K-star AI coding tool, and force-pushed a credential-stealing Shai-Hulud payload to the main branch. The ruff …

  2. story
  3. comment
    Comment #48393621

    [flagged]

  4. story
  5. story
  6. comment
    Comment #48198131

    Three malicious versions of Microsoft's official durabletask Python SDK were published to PyPI on May 19, 2026. The compromised package silently downloads and executes a 28 KB payl…

  7. story
  8. story
  9. story
  10. comment
    Comment #45257079

    The popular @ctrl/tinycolor package, which receives over 2 million weekly downloads, has been compromised along with more than 40 other packages across multiple maintainers. This a…

  11. story
  12. comment
    Comment #44663249

    This article explores how AI coding agents (GitHub Copilot, Claude Code, etc.) operating in CI/CD environments introduce novel security risks that traditional EDR solutions can't d…

  13. story
  14. comment
    Comment #43376513

    @rahulr0609 https://github.com/step-security/changed-files will forever remain free, and the community can use it without requiring a StepSecurity subscription.

  15. comment
    Comment #43374988

    Due to the ongoing security incident involving the tj-actions/changed-files Action, we at StepSecurity have provided a secure, drop-in replacement: step-security/changed-files. We …

  16. comment
    Comment #43373424

    Thank you, cyrnel, for the feedback! We are trying our best to help serve the community. Now, we have separate recovery steps for general users and our enterprise customers.

  17. comment
    Comment #43368364

    Disclaimer: I am a co-founder of StepSecurity. StepSecurity Harden-Runner detected this security incident by continuously monitoring outbound network calls from GitHub Actions work…

  18. story
    Show HN: GitHub Actions Goat – Deliberately Vulnerable CI/CD Environment

    GitHub Actions Goat is an open-source educational project that simulates common security attacks and vulnerabilities in a GitHub Actions CI/CD environment and shows how to defend a…

  19. story