312 Followers
597 Following
1.7K Posts

Irish, 20 years experience in Security, do a bit of everything. Expert in nothing except Powerpoint and fixing broken processes.

Tweets/Toots are a mixture of #infosec, #hiking, #ireland and anything that makes me smile.

Tokenmaxxers logging into GitHub Copilot this week
Microsoft: one day later on we'll think about security and compliance in the product we just launched.

An internal Microsoft strategy document says that the plan for its just-announced “Scout” personal assistant AI is to “make people addicted” to the tool before rolling out additional functionality.

The document notes that “security and compliance” are important things to figure out moving forward.

https://www.404media.co/microsoft-wants-to-make-people-addicted-to-scout-its-new-ai-assistant-internal-documents-reveal/

Microsoft Wants to 'Make People Addicted' to its New AI Assistant, Internal Documents Reveal

Planning documents for "Scout" say the plan is to "make people addicted" to the tool before adding new features.

404 Media

A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link.

https://www.bleepingcomputer.com/news/security/vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click/

VS Code zero-day lets hackers steal GitHub tokens in one click

A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link.

BleepingComputer
Me watching Bake-off: You fool! You can't dip the walnut whirl in the tempered chocolate; you have to drizzle over the top to achieve the characteristic wobble of the coffee ganache, Parisian café-style!
Me baking at home: I forgot to put apples in the apple pie.
When assembling your IKEA dog, please make sure that you follow the instructions carefully ...

GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.

https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/

GitHub confirms breach of 3,800 repos via malicious VSCode extension

GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.

BleepingComputer

New from Nightmare-Eclipse, we have MiniPlasma

Works reliably to get a SYSTEM cmd.exe prompt on Win11 (including 26H1) with May's updates. Is reportedly a failure to properly fix CVE-2020-17103. I'll note that it does not seem to work on the latest Insider Preview Canary Windows 11.

I will likely be one of the first people banging the drum to patch and mitigate if any of the recent AI vulns results in serious harm. Otherwise, keep calm and carry on patching as usual.
AI saves you time by helping you write emails. You can now use that time saved to catch up on the long AI slop emails you’re now receiving from everyone else.