Viewing profile — kurmiashish
kurmiashish
HN member- Joined
- Thu, Sep 24, 2020, 6:05 AM UTC
- HN karma
- 375
- Public activity
- 19 items
- HN profile
- View on Hacker News ↗
About kurmiashish
No profile information was provided.
Recent public activity
-
comment
Comment #48452411
An attacker hijacked a co-founder's GitHub account for gpt-pilot, a 33K-star AI coding tool, and force-pushed a credential-stealing Shai-Hulud payload to the main branch. The ruff …
- story
-
comment
Comment #48393621
[flagged]
- story
- story
-
comment
Comment #48198131
Three malicious versions of Microsoft's official durabletask Python SDK were published to PyPI on May 19, 2026. The compromised package silently downloads and executes a 28 KB payl…
- story
- story
- story
-
comment
Comment #45257079
The popular @ctrl/tinycolor package, which receives over 2 million weekly downloads, has been compromised along with more than 40 other packages across multiple maintainers. This a…
- story
-
comment
Comment #44663249
This article explores how AI coding agents (GitHub Copilot, Claude Code, etc.) operating in CI/CD environments introduce novel security risks that traditional EDR solutions can't d…
- story
-
comment
Comment #43376513
@rahulr0609 https://github.com/step-security/changed-files will forever remain free, and the community can use it without requiring a StepSecurity subscription.
-
comment
Comment #43374988
Due to the ongoing security incident involving the tj-actions/changed-files Action, we at StepSecurity have provided a secure, drop-in replacement: step-security/changed-files. We …
-
comment
Comment #43373424
Thank you, cyrnel, for the feedback! We are trying our best to help serve the community. Now, we have separate recovery steps for general users and our enterprise customers.
-
comment
Comment #43368364
Disclaimer: I am a co-founder of StepSecurity. StepSecurity Harden-Runner detected this security incident by continuously monitoring outbound network calls from GitHub Actions work…
-
story
Show HN: GitHub Actions Goat – Deliberately Vulnerable CI/CD Environment
GitHub Actions Goat is an open-source educational project that simulates common security attacks and vulnerabilities in a GitHub Actions CI/CD environment and shows how to defend a…
- story