367 Followers
123 Following
939 Posts

Things are not always what they seem

Redfin | Rent Head of Information Security

Former Ubisoft Director of Security Operations
Microsoft Alumni | Former Director of MSRC's Cloud Incident Response | He/Him/Hrm | Philosopher & Ninja

SANS:
GCIH #16353 - Cerified Incident Handler
GWAPT #3274- Web Application Pen Tester
GXPN #164 - Exploit Researcher and Advanced Penetration Tester

The Take 9 "Count Before You Click" launch party was so much fun!
This campaign is very dear to me since I grew up with Sesame Street. Now Count Von Count is helping Take 9's mission to encourage people to practice good online security mindfulness by pausing for 9 seconds before you click! 💯👩‍💻

@PauseTake9 #take9 #pausetake9 @craignewmark

The Miasma worm has evolved to now target & infect Ai Agent Tools like, Cursor, Claude, VS Code + Ai Agent Extensions, etc via SessionStart Hooks / post-install initialization steps. We are no longer just looking at infection via Packages, Libraries, Dependencies, or Extensions, but now also Ai Cfgs as well.

Having controls in place for settings.json for Hooks is essential.

If you do not have your code sources on lockdown, you run the risk of an upstream cloned source infecting your Ai-enhanced toolchains via these hooks by simply opening your editor and browsing to a code directory containing an infected cfg file.

https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents

https://code.visualstudio.com/docs/enterprise/ai-settings#_enable-or-disable-hooks

https://code.claude.com/docs/en/hooks#disable-or-remove-hooks

Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents - StepSecurity

On June 5, 2026, the Miasma worm campaign reached Microsoft's Azure GitHub organizations. GitHub disabled 73 repositories across four Microsoft GitHub organizations after a malicious commit was pushed to the Azure/durabletask repository using a previously compromised contributor account. The attack planted configuration files that execute a credential-harvesting payload when a developer opens the repository in Claude Code, Gemini CLI, Cursor, or VS Code.

Wrote a thing on Microsoft’s stance that not following their “responsible disclosure” process is criminal activity https://doublepulsar.com/microsofts-stance-on-zero-day-exploits-is-a-dumpster-fire-of-their-own-making-0946117940a4?postPublishedType=repub
Microsoft’s stance on zero day exploits is a dumpster fire of their own making

Nightmare Eclipse vs Microsoft risks turning into a wildfire of corporate protection over cyber defence.

Medium
@GossiTheDog , can we get a signal boost? Cooldown enforcement on Extensions, Packages, and Plugins are Table stakes and should not be optional or missing features from MS.

Threat intel and Cybersecurity research firms: if you're not providing RSS feeds to your blog, you're hurting your brand.

Whatever traffic you think you're driving to the site by preventing analysts from ingesting feeds is outweighed by the reputational damage of not providing a service we expect and rely on.

And if your reason is because it's hard behind Cloudflare, well, you're telling on yourself twice.

If you are a GitHub Enterprise Server customer, you will need to take action. GitHub announced that one of the keys compromised by the threat actor breach was a signing key.

https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/

Investigating unauthorized access to GitHub-owned repositories

If any impact is discovered, customers will be notified via established incident response and notification channels.

The GitHub Blog
@briankrebs I can get you bootstrapped. What's the best means to get you my contact info.

@briankrebs can we get a piece on the state of package/plugin/extensions Marketplaces being unconscionably behind on hygiene controls that have resulted in these supply chain worms?

Lack of MFA for publishers, lack of hygiene control on 3rd party submitted content, lack of cool down timers on packages/clients to protect themselves from rapidly spreading infections.

The whole framework has been ripe for exploitation. The garden has been left poorly tended we are now subject to the invasion of the worms as a result.

@zombie042 I agree!

Lets change the story!

Give devs the time to Ship Higher Quality Code! Hold product owners accountable for setting tight arbitrary due dates on feature releases.

Move the slider on rewards and incentives from shipping features fast, to shipping quality products!

Move the slider to the left from BugBounty payments, to BugFix payments!

Visual Studio Code Extensions lack a means of enforcing a minimum age to protect against updates that spread worms. There is a feature request to compel Microsoft to add this festure functionality, it only has 212 likes today.
Please help give it a BIG signal boost!

https://github.com/Microsoft/vscode/issues/316867

Security: minimumReleaseAge setting for mitigating supply chain attacks on extensions · Issue #316867 · microsoft/vscode

In the last years, supply chain attacks have increased dramatically. A few examples in the VS Code extension ecosystem: AI-Slop ransomware test sneaks on to VS Code marketplace - BleepingComputer M...

GitHub