GitHub已因疑似Miasma蠕虫感染而下线了70多个Microsoft存储库。该蠕虫损害了贡献者帐户,使其能够执行恶意代码并攻击CI/CD管道。攻击者的目标是窃取云密钥和开发人员工具配置。 AI
影响 受损的CI/CD管道和窃取的云密钥凸显了AI驱动的攻击对开发基础设施日益增长的威胁。
排序理由 影响平台及其用户的安全事件。
在 Mastodon — fosstodon.org 阅读 →
AI 生成摘要 · Google Gemini · 来自 3 个来源。 我们如何撰写摘要 →
GitHub已因疑似Miasma蠕虫感染而下线了70多个Microsoft存储库。该蠕虫损害了贡献者帐户,使其能够执行恶意代码并攻击CI/CD管道。攻击者的目标是窃取云密钥和开发人员工具配置。 AI
影响 受损的CI/CD管道和窃取的云密钥凸显了AI驱动的攻击对开发基础设施日益增长的威胁。
排序理由 影响平台及其用户的安全事件。
在 Mastodon — fosstodon.org 阅读 →
AI 生成摘要 · Google Gemini · 来自 3 个来源。 我们如何撰写摘要 →
Miasma worm shapeshifts, but cloud secret-scouting remains the goal
# Microsoft shut down over 70 # GitHub # repositories , including those related to # Azure and # AI # codingagents , after a data breach. # Hackers planted # malware in the repositories, harvesting credentials when opened in AI coding tools like Claude Code and Gemini CLI. The br…
# GitHub disabled over 70 # Microsoft repositories after detecting a Miasma worm infection that compromised contributor accounts to execute malicious code. The attack targeted CI/CD pipelines in an effort to exfiltrate cloud secrets and developer tool configurations. https://www.…