Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Today in InfoSec Job Security News:

Today in InfoSec Job Security News:

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
84 Indlæg 64 Posters 18 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Today in InfoSec Job Security News:

    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

    chengdulittlea@mastodon.artC This user is from outside of this forum
    chengdulittlea@mastodon.artC This user is from outside of this forum
    chengdulittlea@mastodon.art
    wrote sidst redigeret af
    #50

    @GossiTheDog but... Do these repositories all not have any review processes for their PRs?

    1 Reply Last reply
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      Today in InfoSec Job Security News:

      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

      fritzadalis@infosec.exchangeF This user is from outside of this forum
      fritzadalis@infosec.exchangeF This user is from outside of this forum
      fritzadalis@infosec.exchange
      wrote sidst redigeret af
      #51

      @GossiTheDog
      So just make a bot that goes around behind claude and files a vuln bug and lists the revert as the fix.

      fritzadalis@infosec.exchangeF 1 Reply Last reply
      0
      • fritzadalis@infosec.exchangeF fritzadalis@infosec.exchange

        @GossiTheDog
        So just make a bot that goes around behind claude and files a vuln bug and lists the revert as the fix.

        fritzadalis@infosec.exchangeF This user is from outside of this forum
        fritzadalis@infosec.exchangeF This user is from outside of this forum
        fritzadalis@infosec.exchange
        wrote sidst redigeret af
        #52

        @GossiTheDog
        Nvm these are commits, not prs.

        1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Today in InfoSec Job Security News:

          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

          seism0saurus@infosec.exchangeS This user is from outside of this forum
          seism0saurus@infosec.exchangeS This user is from outside of this forum
          seism0saurus@infosec.exchange
          wrote sidst redigeret af
          #53

          @GossiTheDog

          Is there a cwe (common weakness enumeration) for AI slop usage already?

          1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            Today in InfoSec Job Security News:

            I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

            So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

            https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

            As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

            sassinake@mastodon.socialS This user is from outside of this forum
            sassinake@mastodon.socialS This user is from outside of this forum
            sassinake@mastodon.social
            wrote sidst redigeret af
            #54

            @GossiTheDog

            fuck.

            1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Today in InfoSec Job Security News:

              I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

              So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

              https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

              As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

              apples_and_pears@mastodon.worldA This user is from outside of this forum
              apples_and_pears@mastodon.worldA This user is from outside of this forum
              apples_and_pears@mastodon.world
              wrote sidst redigeret af
              #55

              @GossiTheDog I'm anti-AI. I used program generators long ago - they didn't work. They aren't maintainable. Major updates required complete rewrites.

              Now there's AI. It's a manager's wet dream...until it isn't.

              ...but look how productive AI is. It can whip out code as fast as a gossip can spread noise. Sure, there will be glitches, but they'll be fixed when found.

              What about the $$$$$ liability of glitches that are not found?

              1 Reply Last reply
              0
              • carpetbomberz@mastodon.onlineC This user is from outside of this forum
                carpetbomberz@mastodon.onlineC This user is from outside of this forum
                carpetbomberz@mastodon.online
                wrote sidst redigeret af
                #56

                @funnymonkey @GossiTheDog We don't need Skyntr becoming sentient to trigger the End o' Days.

                We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

                carpetbomberz@mastodon.onlineC 1 Reply Last reply
                0
                • carpetbomberz@mastodon.onlineC carpetbomberz@mastodon.online

                  @funnymonkey @GossiTheDog We don't need Skyntr becoming sentient to trigger the End o' Days.

                  We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

                  carpetbomberz@mastodon.onlineC This user is from outside of this forum
                  carpetbomberz@mastodon.onlineC This user is from outside of this forum
                  carpetbomberz@mastodon.online
                  wrote sidst redigeret af
                  #57

                  @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

                  sassinake@mastodon.socialS 1 Reply Last reply
                  0
                  • carpetbomberz@mastodon.onlineC carpetbomberz@mastodon.online

                    @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

                    sassinake@mastodon.socialS This user is from outside of this forum
                    sassinake@mastodon.socialS This user is from outside of this forum
                    sassinake@mastodon.social
                    wrote sidst redigeret af
                    #58

                    @carpetbomberz @funnymonkey @GossiTheDog

                    this. Exactly this.

                    1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      Today in InfoSec Job Security News:

                      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                      gerhardd@olching.socialG This user is from outside of this forum
                      gerhardd@olching.socialG This user is from outside of this forum
                      gerhardd@olching.social
                      wrote sidst redigeret af
                      #59

                      @GossiTheDog That #claude #AI has been created to solve the „we have too much electricity“ problem.

                      1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Today in InfoSec Job Security News:

                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                        jab01701mid@mastodon.socialJ This user is from outside of this forum
                        jab01701mid@mastodon.socialJ This user is from outside of this forum
                        jab01701mid@mastodon.social
                        wrote sidst redigeret af
                        #60

                        @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

                        jab01701mid@mastodon.socialJ 1 Reply Last reply
                        0
                        • jab01701mid@mastodon.socialJ jab01701mid@mastodon.social

                          @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

                          jab01701mid@mastodon.socialJ This user is from outside of this forum
                          jab01701mid@mastodon.socialJ This user is from outside of this forum
                          jab01701mid@mastodon.social
                          wrote sidst redigeret af
                          #61

                          @GossiTheDog "AI" is the cryptocurrency of IT.

                          1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Today in InfoSec Job Security News:

                            I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                            So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                            https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                            As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                            vlkr@social.tchncs.deV This user is from outside of this forum
                            vlkr@social.tchncs.deV This user is from outside of this forum
                            vlkr@social.tchncs.de
                            wrote sidst redigeret af
                            #62

                            @GossiTheDog https://github.com/claude right now showing "Something went wrong, please refresh the page to try again." Yeah, dude.

                            crazyeddie@mastodon.socialC 1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              Today in InfoSec Job Security News:

                              I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                              So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                              https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                              As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                              vv@solarpunk.moeV This user is from outside of this forum
                              vv@solarpunk.moeV This user is from outside of this forum
                              vv@solarpunk.moe
                              wrote sidst redigeret af
                              #63

                              @GossiTheDog i keep waiting for a scandal to break out about this, but it never comes

                              1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                Today in InfoSec Job Security News:

                                I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                c64whiz@oldbytes.spaceC This user is from outside of this forum
                                c64whiz@oldbytes.spaceC This user is from outside of this forum
                                c64whiz@oldbytes.space
                                wrote sidst redigeret af
                                #64

                                @GossiTheDog

                                Makes me wonder if this is a effort by "closed source" to disrupt/poison/discredit open source? 🤔

                                kiernian@infosec.exchangeK 1 Reply Last reply
                                0
                                • draeath@infosec.exchangeD draeath@infosec.exchange

                                  @nihkeys @DJGummikuh @GossiTheDog I don't think that phrase allows for incompetency in design. The purpose is what was intended, not what actually results. There is a distinction.

                                  azuaron@cyberpunk.lolA This user is from outside of this forum
                                  azuaron@cyberpunk.lolA This user is from outside of this forum
                                  azuaron@cyberpunk.lol
                                  wrote sidst redigeret af
                                  #65

                                  @draeath @nihkeys @DJGummikuh @GossiTheDog If it was an accident, or incompetence, then it would be rapidly corrected.

                                  If it's not rapidly corrected, then it is the purpose.

                                  1 Reply Last reply
                                  0
                                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                    Today in InfoSec Job Security News:

                                    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                    perigee@rage.loveP This user is from outside of this forum
                                    perigee@rage.loveP This user is from outside of this forum
                                    perigee@rage.love
                                    wrote sidst redigeret af
                                    #66

                                    @GossiTheDog @deliberately_me oh goodie. Our global repository has been compromised by a worm.

                                    1 Reply Last reply
                                    0
                                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                      Today in InfoSec Job Security News:

                                      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                      synlogic4242@social.vivaldi.netS This user is from outside of this forum
                                      synlogic4242@social.vivaldi.netS This user is from outside of this forum
                                      synlogic4242@social.vivaldi.net
                                      wrote sidst redigeret af
                                      #67

                                      @GossiTheDog loltears. ie. fools suffer consequences of being fools, but at scale

                                      1 Reply Last reply
                                      0
                                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                        Today in InfoSec Job Security News:

                                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                        el0j@mastodon.gamedev.placeE This user is from outside of this forum
                                        el0j@mastodon.gamedev.placeE This user is from outside of this forum
                                        el0j@mastodon.gamedev.place
                                        wrote sidst redigeret af
                                        #68

                                        @GossiTheDog Fortunately, I can choose to not engage.

                                        1 Reply Last reply
                                        0
                                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                          Today in InfoSec Job Security News:

                                          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                          tknarr@mstdn.socialT This user is from outside of this forum
                                          tknarr@mstdn.socialT This user is from outside of this forum
                                          tknarr@mstdn.social
                                          wrote sidst redigeret af
                                          #69

                                          @GossiTheDog I think @timbray might be interested in that too.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper