Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
louislang
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
Highly-Targeted Attacks Continue to Plague NPM
(blog.phylum.io)
4 points
by
louislang
3y ago
|
0 comments
32.
▲
The untold history of today’s Russian-speaking hackers
(ft.com)
4 points
by
louislang
3y ago
|
1 comments
33.
▲
Women Rising in Esports and Gaming Domains
(theopgaming.com)
1 points
by
louislang
3y ago
|
0 comments
34.
▲
.NET developers alert: Moq NuGET package exfiltrates user emails from Git
(snyk.io)
2 points
by
louislang
3y ago
|
0 comments
35.
▲
VED-eBPF: Kernel Exploit and Rootkit Detection Using eBPF
(github.com)
2 points
by
louislang
3y ago
|
0 comments
36.
▲
by
louislang
3y ago
It's basically managed by a TOML file, so should be able to specify something like that. If that's not to your liking, you can extend the CLI using Typescript and make it do whatever you want. If you have any questions/issues
37.
▲
by
louislang
3y ago
We ( https://phylum.io ) actually open sourced our sandbox for this exact purpose. https://github.com/phylum-dev/birdcage It's baked into our CLI and supports limiting access to network, disk, etc. durin
38.
▲
by
louislang
3y ago
Thanks, we report _many_ of these every day to all the ecosystems. It's wild how many malware packages get released. Doing our best to help clean up these ecosystems for everyone!
39.
▲
by
louislang
3y ago
I'm co-founder of Phylum ( https://phylum.io ), the group that originally identified/reported this campaign back in June [1] and that Github references [2] in their security alert. Happy to answer any questions about thi
40.
▲
by
louislang
3y ago
I'm one of the co-founders of Phylum (referenced in the Github blog post; https://phylum.io ). Happy to answer any questions about this campaign or software supply chain attacks in general. In this case, there is follow on a
41.
▲
by
louislang
3y ago
No questions, just wanted to say congrats!
42.
▲
by
louislang
3y ago
> My airplane flying friend and I derive pleasure from a clean, by-the-book (by-the-documentation tbh) solution. I'm not too keen on leaving my mark on a codebase. Executing in a deterministic and expected way, to me, is _passion_.
43.
▲
by
louislang
3y ago
This is super interesting! How'd you stumble on this?
44.
▲
by
louislang
3y ago
This is really cool work, glad to see someone tackling this! Can I assume this will get rolled out into gitlab natively?
45.
▲
by
louislang
3y ago
You're not wrong. We (Phylum) have seen and called out a security company for typosquatting a popular package as a means of advertising. It felt gross to impact random devs for marketing...
46.
▲
by
louislang
3y ago
We've seen a handful of individuals just go to PyPi or NPM and search for _something_ loosely related to what they need, and just blindly install it. I got a report yesterday of someone that did this with a Python package; similar setu
47.
▲
by
louislang
3y ago
Full disclosure: I'm one of the co-founders of Phylum. I can absolutely assure you, we have no affiliation with these packages. We end up reporting much more malicious packages than these every single day. We wouldn't risk harming
48.
▲
by
louislang
4y ago
Having been through the pain of SOC2 Type 2, I'll consider this a big announcement as well!
49.
▲
How Discord Stores Trillions of Messages
(discord.com)
1 points
by
louislang
4y ago
|
0 comments
50.
▲
A PyPI typosquatting campaign post-mortem
(blog.phylum.io)
3 points
by
louislang
4y ago
|
0 comments
51.
▲
by
louislang
4y ago
I think it would go down, but by how much? And is it significant enough to remove the requirement to vent outside?
52.
▲
by
louislang
4y ago
What impact does an enclosure with a filter have on the emission of particles and VOCs?
53.
▲
Another Tale of IBM I (AS/400) Hacking (2022)
(blog.silentsignal.eu)
61 points
by
louislang
4y ago
|
13 comments
54.
▲
by
louislang
4y ago
If I had to guess, quite a few. I've reported my fair share of security issues and a number of them started out by accident.
55.
▲
by
louislang
4y ago
I'm always amazed how often that happens. Again, excellent finding.
56.
▲
by
louislang
4y ago
Great find! Were you actively looking, or did you just stumble on something that set off your spidey-sense?
57.
▲
by
louislang
4y ago
We report them when we find them (to Github, PyPI, NPM, etc). Unfortunately the process on the other side isn't super quick. For example, we reported some malware to NPM on Dec 31, 2022 and received an email from them stating they were
58.
▲
by
louislang
4y ago
Been working on this exact thing for nearly two years at https://www.phylum.io . We identified and reported about 1.2k packages in ecosystems like npm, pypi and others last year. GitHub app that checks your PRs for malware. We al
59.
▲
by
louislang
4y ago
We’ve ( https://www.phylum.io ) been tracking this actor as well. There are more packages than this blog post notes, including: fredli, derkpy, and fredmi. The first packages from this actor appeared on Jan 1. A bit of work has be
60.
▲
Malicious PyPI packages create Cloudflare Tunnels to bypass firewalls
(bleepingcomputer.com)
5 points
by
louislang
4y ago
|
0 comments
More ›