I’m concerned stuff like this will lead to a “dark forest” scenario, in which the risks of open source outweigh the benefits. Not today, but it's not impossible tomorrow.
https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
I’m concerned stuff like this will lead to a “dark forest” scenario, in which the risks of open source outweigh the benefits. Not today, but it's not impossible tomorrow.
https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/mttaggart/statuses/116154929380149214 on your instance and quote it. (Note that quoting is not supported in Mastodon.)