Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. Today in InfoSec Job Security News:

Today in InfoSec Job Security News:

Scheduled Pinned Locked Moved Uncategorized
133 Posts 102 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Kevin BeaumontG Kevin Beaumont

    Today in InfoSec Job Security News:

    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

    seism0saurusS This user is from outside of this forum
    seism0saurusS This user is from outside of this forum
    seism0saurus
    wrote last edited by
    #62

    @GossiTheDog

    Is there a cwe (common weakness enumeration) for AI slop usage already?

    1 Reply Last reply
    0
    • kwayk42K kwayk42

      @da_667 @GossiTheDog

      kwayk42K This user is from outside of this forum
      kwayk42K This user is from outside of this forum
      kwayk42
      wrote last edited by
      #63

      @da_667 @GossiTheDog took me a while but I finally thought of something :

      Who says AI hasn't generated any real value? It's doing wonders for the threat actors

      1 Reply Last reply
      0
      • Kevin BeaumontG Kevin Beaumont

        Today in InfoSec Job Security News:

        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

        funnymonkeyF This user is from outside of this forum
        funnymonkeyF This user is from outside of this forum
        funnymonkey
        wrote last edited by
        #64

        @GossiTheDog

        OMFG.

        Eric LiknessC 1 Reply Last reply
        0
        • Kevin BeaumontG Kevin Beaumont

          Today in InfoSec Job Security News:

          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

          Sassinake! - ⊃∪∩⪽S This user is from outside of this forum
          Sassinake! - ⊃∪∩⪽S This user is from outside of this forum
          Sassinake! - ⊃∪∩⪽
          wrote last edited by
          #65

          @GossiTheDog

          fuck.

          1 Reply Last reply
          0
          • Kevin BeaumontG Kevin Beaumont

            Today in InfoSec Job Security News:

            I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

            So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

            https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

            As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

            DaveA This user is from outside of this forum
            DaveA This user is from outside of this forum
            Dave
            wrote last edited by
            #66

            @GossiTheDog I'm anti-AI. I used program generators long ago - they didn't work. They aren't maintainable. Major updates required complete rewrites.

            Now there's AI. It's a manager's wet dream...until it isn't.

            ...but look how productive AI is. It can whip out code as fast as a gossip can spread noise. Sure, there will be glitches, but they'll be fixed when found.

            What about the $$$$$ liability of glitches that are not found?

            1 Reply Last reply
            0
            • funnymonkeyF funnymonkey

              @GossiTheDog

              OMFG.

              Eric LiknessC This user is from outside of this forum
              Eric LiknessC This user is from outside of this forum
              Eric Likness
              wrote last edited by
              #67

              @funnymonkey @GossiTheDog

              We don't need Skynet becoming sentient to trigger the End o' Days.

              We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

              Eric LiknessC 1 Reply Last reply
              0
              • Eric LiknessC Eric Likness

                @funnymonkey @GossiTheDog

                We don't need Skynet becoming sentient to trigger the End o' Days.

                We got Claude, happily vibing/making 2.1M commits while we were asleep.😴

                Eric LiknessC This user is from outside of this forum
                Eric LiknessC This user is from outside of this forum
                Eric Likness
                wrote last edited by
                #68

                @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

                Sassinake! - ⊃∪∩⪽S 1 Reply Last reply
                0
                • Eric LiknessC Eric Likness

                  @funnymonkey @GossiTheDog Insert Mickey Mouse as the Sorcerer's Apprentice, and all those animated mops carrying pails of water...

                  Sassinake! - ⊃∪∩⪽S This user is from outside of this forum
                  Sassinake! - ⊃∪∩⪽S This user is from outside of this forum
                  Sassinake! - ⊃∪∩⪽
                  wrote last edited by
                  #69

                  @carpetbomberz @funnymonkey @GossiTheDog

                  this. Exactly this.

                  1 Reply Last reply
                  0
                  • Kevin BeaumontG Kevin Beaumont

                    Today in InfoSec Job Security News:

                    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                    Gerhard D.G This user is from outside of this forum
                    Gerhard D.G This user is from outside of this forum
                    Gerhard D.
                    wrote last edited by
                    #70

                    @GossiTheDog That #claude #AI has been created to solve the „we have too much electricity“ problem.

                    1 Reply Last reply
                    0
                    • Kevin BeaumontG Kevin Beaumont

                      Today in InfoSec Job Security News:

                      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                      John BreenJ This user is from outside of this forum
                      John BreenJ This user is from outside of this forum
                      John Breen
                      wrote last edited by
                      #71

                      @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

                      John BreenJ 1 Reply Last reply
                      0
                      • John BreenJ John Breen

                        @GossiTheDog It's almost like, maybe, only humans should program computers. Computers should not be submitting and merging their own PRs, am I right ?

                        John BreenJ This user is from outside of this forum
                        John BreenJ This user is from outside of this forum
                        John Breen
                        wrote last edited by
                        #72

                        @GossiTheDog "AI" is the cryptocurrency of IT.

                        1 Reply Last reply
                        0
                        • Kevin BeaumontG Kevin Beaumont

                          Today in InfoSec Job Security News:

                          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                          vlkrV This user is from outside of this forum
                          vlkrV This user is from outside of this forum
                          vlkr
                          wrote last edited by
                          #73

                          @GossiTheDog https://github.com/claude right now showing "Something went wrong, please refresh the page to try again." Yeah, dude.

                          crazyeddieC 1 Reply Last reply
                          0
                          • Kevin BeaumontG Kevin Beaumont

                            Today in InfoSec Job Security News:

                            I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                            So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                            https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                            As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                            encrypted.vvhispers 💫V This user is from outside of this forum
                            encrypted.vvhispers 💫V This user is from outside of this forum
                            encrypted.vvhispers 💫
                            wrote last edited by
                            #74

                            @GossiTheDog i keep waiting for a scandal to break out about this, but it never comes

                            1 Reply Last reply
                            0
                            • Kevin BeaumontG Kevin Beaumont

                              Today in InfoSec Job Security News:

                              I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                              So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                              https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                              As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                              C64WhizC This user is from outside of this forum
                              C64WhizC This user is from outside of this forum
                              C64Whiz
                              wrote last edited by
                              #75

                              @GossiTheDog

                              Makes me wonder if this is a effort by "closed source" to disrupt/poison/discredit open source? 🤔

                              KiernianK naikrovekN 2 Replies Last reply
                              0
                              • draeathD draeath

                                @nihkeys @DJGummikuh @GossiTheDog I don't think that phrase allows for incompetency in design. The purpose is what was intended, not what actually results. There is a distinction.

                                AzuaronA This user is from outside of this forum
                                AzuaronA This user is from outside of this forum
                                Azuaron
                                wrote last edited by
                                #76

                                @draeath @nihkeys @DJGummikuh @GossiTheDog If it was an accident, or incompetence, then it would be rapidly corrected.

                                If it's not rapidly corrected, then it is the purpose.

                                1 Reply Last reply
                                0
                                • Kevin BeaumontG Kevin Beaumont

                                  Today in InfoSec Job Security News:

                                  I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                  So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                  https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                  As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                  Mal 甄/kalessin/PeriP This user is from outside of this forum
                                  Mal 甄/kalessin/PeriP This user is from outside of this forum
                                  Mal 甄/kalessin/Peri
                                  wrote last edited by
                                  #77

                                  @GossiTheDog @deliberately_me oh goodie. Our global repository has been compromised by a worm.

                                  Reiner Jung 🇬🇱 🇺🇦 🇪🇺P 1 Reply Last reply
                                  0
                                  • Kevin BeaumontG Kevin Beaumont

                                    Today in InfoSec Job Security News:

                                    I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                    So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                    https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                    As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                    synlogic4242S This user is from outside of this forum
                                    synlogic4242S This user is from outside of this forum
                                    synlogic4242
                                    wrote last edited by
                                    #78

                                    @GossiTheDog loltears. ie. fools suffer consequences of being fools, but at scale

                                    1 Reply Last reply
                                    0
                                    • Kevin BeaumontG Kevin Beaumont

                                      Today in InfoSec Job Security News:

                                      I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                      So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                      https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                      As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                      Eddy JanssonE This user is from outside of this forum
                                      Eddy JanssonE This user is from outside of this forum
                                      Eddy Jansson
                                      wrote last edited by
                                      #79

                                      @GossiTheDog Fortunately, I can choose to not engage.

                                      1 Reply Last reply
                                      0
                                      • Kevin BeaumontG Kevin Beaumont

                                        Today in InfoSec Job Security News:

                                        I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                        So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                        https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                        As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                        Todd KnarrT This user is from outside of this forum
                                        Todd KnarrT This user is from outside of this forum
                                        Todd Knarr
                                        wrote last edited by
                                        #80

                                        @GossiTheDog I think @timbray might be interested in that too.

                                        1 Reply Last reply
                                        0
                                        • Kevin BeaumontG Kevin Beaumont

                                          Today in InfoSec Job Security News:

                                          I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

                                          So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

                                          https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

                                          As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

                                          G This user is from outside of this forum
                                          G This user is from outside of this forum
                                          Atomic Orbitals
                                          wrote last edited by
                                          #81

                                          @GossiTheDog Not just bad vibes, but the *same* bad vibes repeated endlessly!

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups