"A week-long automated attack campaign targeted CI/CD pipelines across major open source repositories, achieving remote code execution in at least 4 out of 5 targets"

๐Ÿ‘€๐Ÿ‘€๐Ÿ‘€๐Ÿ‘€๐Ÿ‘€

stepsecurity.io/blog/hackerbot

0
5
1

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/campuscodi/statuses/116154291574332497 on your instance and quote it. (Note that quoting is not supported in Mastodon.)

RE: mastodon.social/@campuscodi/11

> We're entering an era where AI agents attack other AI agents. In this campaign, an AI-powered bot tried to manipulate an AI code reviewer into committing malicious code. The attack surface for software supply chains just got a lot wider.

0