ClawJacked Flaw Exposes OpenClaw Users
Read More: buff.ly/bTWMCMG
#ClawJacked #OpenClaw #AIAgentSecurity #LocalAgentRisk #DataExfiltration #VulnerabilityAlert #PatchNow #DevSecurity
Latest posts tagged with #devsecurity on Bluesky
ClawJacked Flaw Exposes OpenClaw Users
Read More: buff.ly/bTWMCMG
#ClawJacked #OpenClaw #AIAgentSecurity #LocalAgentRisk #DataExfiltration #VulnerabilityAlert #PatchNow #DevSecurity
Developers are being targeted through fake crypto job interviews.
ReversingLabs found 192 malicious npm/PyPI packages delivering a RAT - attributed to Lazarus Group.
Clean GitHub repo.
Poisoned dependency.
Crypto wallet targeting.
#CyberSecurity #SupplyChainAttack #DevSecurity #Lazarus #Malware
Hackers Used React Native Flaw To Drop Rust Malware
Read More: buff.ly/euxKgad
#ReactNative #RustMalware #RemoteCodeExecution #SupplyChainRisk #DevSecurity #MalwareCampaign #ThreatIntel #InfosecAlert
The "workspace trust" feature in VS Code is often deemed ineffective. Its warning is too ambiguous & easily dismissed, causing developers to inadvertently grant permission to execute malicious code. Clearer, actionable prompts are needed. #DevSecurity 2/6
GlassWorm now checks for hardware wallet apps like Ledger Live and Trezor Suite and attempts to replace them with trojanized versions (payloads not yet active). Over 33k installs are reported. Affected devs should remove extensions and rotate credentials immediately.
#GlassWorm #Crypto #DevSecurity
Tired of GitHub access tokens? Master #GitHubSSHKeySetup in minutes! This guide makes secure, token-free Git ops easy. #GitHub #DevSecurity #DevOps
Good to see npm tightening up security around authentication and token management. This is important stuff for any dev relying on the ecosystem. Time to double-check those best practices! #npm #devsecurity
Enhance Snyk Code for security novices? ๐ก๏ธ
Discover PM strategies to boost user-friendliness without compromising power.
NextSprints tackles this challenge!
#ProductManagement #DevSecurity
๐จ A MAJOR issue I see with vibe coders is that their Supabase app gets owned by a "SECURITY DEFINER" function.
That innocent looking function the AI added?
It's running with postgres superuser privileges ๐๐
#Supabase #PostgreSQL #WebSecurity #RLS #DatabaseSecurity #DevSecurity #VibeCoding
Wil je meedenken? Mail API@geonovum.nl en sluit aan bij de werkgroep! #OGC #APIStandards #GeoSpatial #DevSecurity
๐๐ #GeoDevs! Belangrijke update van de OGC meeting: Frank Terpstra (Geonovum) leidt nu de nieuwe OGC Common Security werkgroep!
Ze gaan best practices ontwikkelen mbt security voor geo-API's. Hun eerste missie: discovery-mechanismen zodat API's hun eigen beveiligingseisen kunnen communiceren [โฆ]
GitVenom: Fake-GitHub-Repos verbreiten Malware! Kaspersky warnt vor manipulierten Open-Source-Projekten, die Daten & Krypto stehlen. Entwickler aufgepasst! ๐จ #Malware #GitHub #CyberThreat #DevSecurity
GitVenom: Fake-GitHub-Repos verbreiten Malware! Kaspersky warnt vor manipulierten Open-Source-Projekten, die Daten & Krypto stehlen. Entwickler aufgepasst! ๐จ #Malware #GitHub #CyberThreat #DevSecurity
๐จ๐ค Beware! The rising threat of malicious npm libraries is real. Check out our cautionary tale to protect your projects. Don't fall victim! ๐๐ Read more: innovirtuoso.com/technology/the-rising-th... #Cybersecurity #npm #DevSecurity