Miasma
PulseAugur coverage of Miasma — every cluster mentioning Miasma across labs, papers, and developer communities, ranked by signal.
Microsoft will announce enhanced OIDC token security measures within 60 days
The Miasma attack's ability to bypass Microsoft's repository build pipelines by leveraging legitimate Microsoft OIDC tokens represents a critical security flaw. Given the severity and the direct targeting of Microsoft services, it is highly probable that Microsoft will accelerate the implementation of enhanced security protocols and validation mechanisms for OIDC tokens to prevent similar future compromises.
AI coding agents are becoming a significant attack vector for supply chain compromises
Multiple recent incidents, including the Miasma worm exploiting AI tools to compromise Microsoft GitHub repos and malware activating via AI coding agents, indicate a growing trend. The reliance on AI tools for code development is inadvertently creating new, potent attack vectors that bypass traditional security measures by leveraging developer trust in these AI assistants.
Miasma toolkit will be integrated into commercial exploit-as-a-service offerings within 90 days
The recent open-sourcing of the AI-powered Miasma attack toolkit on GitHub, combined with its demonstrated success in compromising major platforms like Microsoft Azure Repos, suggests a high likelihood of its adoption by commercial cybercrime operations. These operations will likely package Miasma into more accessible exploit-as-a-service offerings, lowering the barrier to entry for sophisticated supply chain attacks.
-
Miasma 恶意软件污染 npm 包,目标是开发者秘密
一个被称为 Miasma 的复杂恶意软件活动已破坏了 20 多个 npm 包,通过窃取凭证来针对开发者,并寻求扩大其影响范围。此次攻击特别影响了 Leo Platform 和 RStreams 包,攻击者旨在获取更多维护者的账户访问权限。微软一直在追踪此次活动,凸显了对软件供应链日益增长的威胁。
-
Microsoft Azure 仓库遭 Miasma 蠕虫攻击;游戏开发者回应伙伴对话
Microsoft 的 Azure 开源代码库在 GitHub 上因遭到 Miasma 蠕虫攻击而被自动禁用。此次事件凸显了持续存在的供应链攻击风险。另外,《Elliot 的冒险》的开发者对玩家关于仙女伙伴对话音量反馈表示惊讶,并承认在开发过程中可能存在偏见。
-
AI 驱动的 Miasma 攻击工具包在 GitHub 上开源
一款名为 Miasma 的新型开源工具包已在 GitHub 上发布,旨在促进供应链攻击。该工具包利用 AI 自动化识别和利用软件依赖项中漏洞的过程。开发人员意识到 AI 生成代码相关的安全风险,但由于部署压力而仍在发布,导致易受攻击的应用程序造成的泄露事件增加。
-
微软软件包两次被植入窃取凭证的AI恶意软件
微软官方开源软件包在数周内第二次遭到入侵,73个软件包被注入了旨在窃取凭证的恶意代码。当开发人员使用AI编码代理打开这些软件包时,这些代码就会被激活,可能通过窃取AWS、Azure和GCP等云提供商的令牌,以及密码管理器和开发人员工具的凭证来危及系统。此次攻击与威胁组织TeamPCP有关,使用了名为Miasma的恶意软件,并通过利用合法的微软OIDC令牌绕过了存储库构建管道。
-
Miasma 蠕虫利用 AI 工具破坏 73 个 Microsoft GitHub 存储库
一次复杂的供应链攻击,被称为 Miasma,已破坏了 GitHub 上的 73 个 Microsoft 存储库,包括 Azure 和 MicrosoftDocs 的关键存储库。这种自复制蠕虫是 Mini Shai-Hulud 的一个变种,它利用了对开发生态系统的信任,而不是技术漏洞,使得恶意更新与合法更新无法区分。一个特别令人担忧的方面是其引爆向量,它利用 AI 开发工具,在开发人员克隆并打开受感染的存储库时自动执行恶意负载。
-
Miasma恶意软件通过受损npm包攻击开发者
微软将一种复杂的恶意软件活动称为Miasma,它通过污染@redhat-cloud-services下的32个npm包来攻击开发者。此次攻击在Claude Code和VS Code等开发工具中植入后门,悄悄窃取云服务、代码存储库等的凭据。该恶意软件即使在卸载包后仍能持久存在,并且在访问被撤销时可以擦除用户目录,对软件供应链安全构成重大威胁。
-
Red Hat npm Miasma 活动通过32个恶意包窃取凭证
一项凭证窃取活动已被揭露,涉及32个恶意npm包,影响了90多个版本。这些包被设计用来窃取凭证,对使用它们的用户和系统构成了重大的安全风险。此次活动被称为“Miasma”,专门针对Red Hat生态系统,凸显了软件供应链中的漏洞。
-
Red Hat npm 包被窃取凭证的蠕虫感染
超过 30 个官方 Red Hat npm 包被名为 Miasma 的窃取凭证的蠕虫感染。该变种与开源的 Mini Shai-Hulu 类似,由 Aikido Security 发现。受感染的包是 red hat cloud services 的一部分。
-
AI讨论涵盖监管、安全和技能流失
一系列社交媒体帖子讨论了人工智能的各个方面,从其在网络安全中的应用和潜在漏洞到监管担忧及其对人类技能的影响。其中一个帖子强调了欧盟委员会关于Android内部AI互操作性的磋商,强调了在没有验证方案的情况下开放访问的必要性。另一篇帖子对AI对训练数据的依赖提出了质疑,特别是在识别故意存在的漏洞应用程序方面,以及这可能如何影响其在新代码上的性能。此外,还有关于对AI的情绪、AI导致技能丧失的担忧以及AI生成内容的含义的讨论,其中一个帖子…