Zed editor vulns.
https://github.com/zed-industries/zed/security/advisories/GHSA-cv6g-cmxc-vw8j
https://github.com/zed-industries/zed/security/advisories/GHSA-29cp-2hmh-hcxj
Zed editor vulns.
https://github.com/zed-industries/zed/security/advisories/GHSA-cv6g-cmxc-vw8j
https://github.com/zed-industries/zed/security/advisories/GHSA-29cp-2hmh-hcxj
@mattly I expect there are a lot of undiscovered / unpublished vulns in all plugin ecosystems. Just look at the issues with the well-funded ones.
@reverseics So what software are you going to buy and destroy while arrogantly harassing researchers?
@reverseics The dream.
@reverseics @briankrebs The worst part is I was already preparing to put up another one on another website so it was an easy copy paste slop job.
@codinghorror @Sempf You better run.
Go hack more MCP shit.
https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/
@huronbikes It's almost like vibe-coding an entire class of product was a bad idea.
RE: https://infosec.exchange/@patrickcmiller/115681402579901898
This had made many people very angry and has been widely regarded as a bad move.
@GossiTheDog Seems like it would be easy to add at least one product as not vulnerable then, wouldn't it? I mean, they put up the advisory and people are talking about it. Why wait to populate it before US West goes on weekend?
RE: https://infosec.exchange/@cR0w/115663720460315600
Still nothing from Cisco...
That's an anus!
I wonder how many people have had the brilliant idea to sidestep password cracking by passing hashes to an LLM or something, hoping it would magically give them the plaintexts. :brdThink:
@GossiTheDog What the LinkedIn fuck is a Chief Hacking Officer?
@CrabbyIT www.linkedin.com/in/gayint
:neocat_bottom:
RE: https://infosec.exchange/@SecurityWriter/115543679693908794
Go hack more AI shit.
@catsalad @briankrebs My mind was blown when I did that in the middle of a demo and a student told me about Ctrl+Shift+T. Saved my ass hundreds of times ever since.
Just another analyst chasing squirrels and pretending to know things.Anything stupid I say can and should be blamed on #AI. I mean, I don't intentionally use AI products, but if the AI snakeoilers can take credit for the things other people produce, they can also take the blame.
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.