After 6 months of thinking about the topic, I dove back into automated open-source #malware analysis this weekend.

The result is the culmination of the lessons I learned building #malcontent: context and maintainability are everything. So I've built something smarter using language ASTs for source, Radare2 for RE, hierarchical traits, and ML for criticality.

#Rust has been an adventure, but a good one. More to share eventually...

Personally, I love this latest viral jab at America's worst president. Inspired by a recent post, I've created tshirt and sticker designs to keep this hilarious meme going.

Get your "LET'S GO TACO" gear today from Ten Thousand Things.

https://www.etsy.com/shop/10kthings?search_query=let%27s+go+taco

#taco #letsgotaco #antimaga #dystopianmalcontent #dystopian #malcontent #trumpisanidiot

Of course, that's not how it works. Only the poor are punished for not having enough money.

20% of profits go to activist groups.

https://www.etsy.com/listing/4306444932/how-much-of-the-national-deficit-do-you

Available as stickers (4 sizes) and tshirts (XS-3X)

#antiMAGA #nokings #dystopian #malcontent #dystopianmalcontent

In a recent interview with the Guardian, Abigail Disney (yes, that Disney), said, “I am of the belief that every billionaire who can’t live on $999 million is kind of a sociopath”

Available as stickers (4 sizes) and tshirts (XS-3X). Order now for the upcoming #nokings protest.

20% of profits will go to activist groups.

https://www.etsy.com/listing/4306252591/the-only-dangerous-minority-is-the-rich

#dystopianmalcontent #dystopian #malcontent #tenthousandthings #10kthings

A quotation from Oliver Wendell Holmes, Sr.

That is what you have to expect if you invent anything that puts an old machine out of fashion, or solve a problem that has puzzled all the world up to your time. There never was a religion founded but its Messiah was called a crank. There never was an idea started that woke up men out of their stupid indifference but its originator was spoken of as a crank.

Oliver Wendell Holmes, Sr. (1809-1894) American poet, essayist, scholar
Article (1890-06), “Over the Teacups,” No. 7, Atlantic Monthly, Vol. 66

Sourcing, notes: wist.info/holmes-sr-oliver-wen…

#quote #quotes #quotation #qotd #acceptance #change #changeagent #crank #crazy #idiot #innovation #invention #malcontent #progress #reform

Yes, #malcontent detected all iterations of the "ultralytics" supply-chain attack. The attackers weren't trying hard to be sneaky, so anyone looking should have detected it, but few are. #supplychainsecurity

Over the last nine months, I've been working on a tool named #malcontent to detect when #malware is inserted into open-source software. While it is far from finished, we released v1.4.0 today, and it's the first release I am genuinely proud of: https://github.com/chainguard-dev/malcontent/releases/tag/v1.4.0

Here's a view of the new UI, shown inspecting the most recent supply-chain attack in the Lottie video player library. Each line prefixed with "+++" is a new, unexpected behavior that it detected.

Release v1.4.0 · chainguard-dev/malcontent

Tool Improvements Modernize terminal output by @tstromberg in #564 brief: highlight evidence by @tstromberg in #566 fix over-indenting in diff mode by @tstromberg in #568 Don't store an empty file...

GitHub
Hot off the personal blog: https://unfinished.bike/detecting-the-lottie-supply-chain-attack-with-malcontent - #malcontent is an #opensource #supply-chain attack detector that @egibs and I have been hacking at during our free time. For more, see https://github.com/chainguard-dev/malcontent
Detecting the Lottie supply-chain attack with malcontent

Some of you may have heard that there was another supply-chain attack against an open-source project yesterday - this time in a Javascrip...

unfinished.bike
Not to sound like a #curmudgeon (a #malcontent if you will) but why don't #parents prevent their #spawn from making noise with utensils when in a public restaurant? How is the partially formed #homosapien to imprint what is rude, #entitled and/or #unconscious behaviour?

👋 My last #introduction was in 2022, so here's an update:

- Security Squad Lead at #Chainguard
- Keenly interested in #InfoSec and #ReliabilityEngineering
- 30 years of experience messing with the Internet & UNIX
- I build bamboo bicycle frames & spend more time tinkering than riding
- Spend my idle time playing #guitar and wandering on 2-wheel EVs
- Live in #Carrboro NC with my wife & kids
- Contributed to 150+ #OpenSource projects including 50+ I've created - #malcontent is my latest.