Incident Report: CVE-2024-YIKES

A series of unfortunate events.

Andrew Nesbitt
@mhoye @andrewnez I don't know what made me laugh more: The satiric CVE or the obviously automatically AI-generated renarration on some vendor's blog 🀣🀣🀣
https://sesamedisk.com/cve-2024-yikes-supply-chain-attack/
CVE-2024-YIKES: A Supply Chain Attack Exposed and How to Prevent It

Learn about the CVE-2024-YIKES supply chain attack, its analysis, root causes, and strategies to prevent similar cybersecurity incidents in software ecosystems.

Sesame Disk
@skyr @mhoye πŸ€¦β€β™‚οΈ
@andrewnez @mhoye and another one πŸ˜‚
https://thecodersblog.com/cve-2024-yikes-incident-report-2026/
"This isn’t a theoretical exercise; it’s a wake-up call" *GASP* can't.... breathe... 🀣🀣🀣
Security Alert: Analyzing CVE-2024-YIKES Incident | The Coders Blog | Home

Deep dive into CVE-2024-YIKES: understand the exploit, impact, and remediation steps for robust protection.

The Coders Blog | Home
@skyr @mhoye and people say that the security industry is dead, look at how fast these companies are responding!
@skyr @andrewnez @mhoye this one smells like slop..
@petko that whole site feels slop-py
@skyr oh, sorry, didn't see the rest of the thread. The joys of fedi :)
@petko no prob 😊
The whole issue made me think of a project:
- conspirators post easily recognicable BS on their sites
- wait for slop sites repeating the shit
- collect them on a blacklist
- browser plugin blocks sites and removes them from search results
πŸŽ‰
@skyr @mhoye this does give me a great idea for a follow up though πŸ€”