Microsoft's open source tools were hacked to steal passwords of AI developers
31–40 of 211 posts
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#32It actually feels like nothing is safe now every day you hear about hacking is it from the ai making development weak or ai is getting strong in hacking
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#33Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#34What follows next is purely speculation and it is based on my own observations and thoughts but based on what I've seen the old RBAC models, while being almost broken before, now it is fully broken, with the fact that now coding assistants and engineers are working on multiple unrelated projects simultaneously - especially working on wild experiments they had no time for previously. The risk of supply chain issue has…
Welp.
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#35What follows next is purely speculation and it is based on my own observations and thoughts but based on what I've seen the old RBAC models, while being almost broken before, now it is fully broken, with the fact that now coding assistants and engineers are working on multiple unrelated projects simultaneously - especially working on wild experiments they had no time for previously. The risk of supply chain issue has…
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#36> steal passwords of AI developers What does this even mean? The malware specifically steals passwords from developers who use AI? From those who develop AI tool? Or it steals API tokens, which serve a similar function as passwords do for humans? Is this what journalism looks like today? Just slap the two holy letters on the title and you get views? (Yes, I read the article. No, I still don't think the title makes se…
VSCode will be used by plenty of non-AI-using developers, and the credential harvester is not specific to AI API tokens, but that 3/4 of the targets are AI coding tools is I assume where the claim comes from.
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#37And we trust these people with the root CA cert in our Secure Boot?
> Individually, any one of the failings described above might be understandable. Taken together, they point to a failure of Microsoft’s organizational controls and governance, and of its corporate culture around security.
Microsoft’s products and services are ubiquitous. It is one of the most important technology companies in the world, if not the most important. This position brings with it utmost and global responsibilities. It requires a security-focused corporate culture of accountability, which starts with the CEO, to ensure that financial or other go-to-market factors do not undermine cybersecurity and the protection of Microsoft’s customers.
> Unfortunately, throughout this review, the Board identified a series of operational and strategic decisions that collectively point to a corporate culture in Microsoft that deprioritized both enterprise security investments and rigorous risk management. These decisions resulted in significant costs and harm for Microsoft customers around the world.
> The Board is convinced that Microsoft should address its security culture.
[0] https://www.cisa.gov/resources-tools/resources/CSRB-Review-S...
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#38The phrasing of the title is loaded and the content phrases it as some kind of fault of open source. Then, which I find the most amusing, proceeds to blame MicroSlop for the attempted suuply chain attack, > Microsoft did not immediately provide the specific number of customers affected, when asked by TechCrunch. Yeah, because that's how open source works. Tech crunch doing hard work no not explain that. > This is Mic…
> I, like many others love to knock on Microslop when I can, but in this case they did the right thing.
I've no idea what your problem with this sentence is. They have an organisational security problem, aided/demonstrated by lack of effort to effectively lockdown GitHub Actions and allowing MRs to circumvent CI/CD.
That this is a Microsoft problem that was present pre-AI is not up for debate. See https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewO...
In the age of AI, it's now endemic and being weaponised.
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#39And the best recommendation security teams can give - keep your SBOM strict, use min release age policy (sounds more like band-aid). That's a scary world to live in.
Based on the news, seems like it is better to not include Microsoft at all in there.
Re: Microsoft's open source tools were hacked to steal passwords of AI developers
#40Earlier quoted context omitted.
What's your post mortem, then? As in - what happened and how should it be read?
Microsoft's open source projects the target of a supply chain attack and they decided to restrict access to understand and limit exposure ? Something a little more 'true' and less targetted?