Earlier quoted context omitted.
'nmp'
I only noticed at goat farming. But anyway, what would a left-justify package do?
Incident Report: CVE-2024-YIKES
91–100 of 187 posts
Re: Incident Report: CVE-2024-YIKES
#92Earlier quoted context omitted.
'nmp'
I only noticed at goat farming. But anyway, what would a left-justify package do?
Re: Incident Report: CVE-2024-YIKES
#93For anyone confused, this is (very good imo) fiction about supply-chain incidents. It had me very worried during a brief scan that it was real though, which made me read it more attentively :)
Re: Incident Report: CVE-2024-YIKES
#94The maintainer of left-justify receives his YubiKey from yubikey-official-store.net. It is a $4 USB drive containing a README that says “lol.” Got me seriously laughing... Such a troll.
Re: Incident Report: CVE-2024-YIKES
#95Re: Incident Report: CVE-2024-YIKES
#96> Day 1, 14:47 UTC — Among the exfiltrated credentials: the maintainer of vulpine-lz4, a Rust library for “blazingly fast Firefox-themed LZ4 decompression.” The library’s logo is a cartoon fox with sunglasses. It has 12 stars on GitHub but is a transitive dependency of cargo itself. I got a bit curious and here is an incomplete list of crates to compromise to be part of the cargo build and that already have a build.r…
Re: Incident Report: CVE-2024-YIKES
#97> Day 1, 14:47 UTC — Among the exfiltrated credentials: the maintainer of vulpine-lz4, a Rust library for “blazingly fast Firefox-themed LZ4 decompression.” The library’s logo is a cartoon fox with sunglasses. It has 12 stars on GitHub but is a transitive dependency of cargo itself. I got a bit curious and here is an incomplete list of crates to compromise to be part of the cargo build and that already have a build.r…
-sys crates are just bindings and doing something else in them is highly suspect. The rest I recognize as being owned by a Rust maintainer like alexcrichton or rustlang itself.
Re: Incident Report: CVE-2024-YIKES
#98For anyone confused, this is (very good imo) fiction about supply-chain incidents. It had me very worried during a brief scan that it was real though, which made me read it more attentively :)
Searching for CVE-2024-YIKES also provides a gallery of AI slop blogs that AI-rewrite the content of this post while being absolutely stone cold serious about it.
Re: Incident Report: CVE-2024-YIKES
#99Re: Incident Report: CVE-2024-YIKES
#100For anyone confused, this is (very good imo) fiction about supply-chain incidents. It had me very worried during a brief scan that it was real though, which made me read it more attentively :)