Today in InfoSec Job Security News:

I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

github.com/search?q=author%3Ac

As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://cyberplace.social/users/GossiTheDog/statuses/116080909947754833 on your instance and quote it. (Note that quoting is not supported in Mastodon.)