Carlini's unprompted talk is one source: https://www.youtube.com/watch?t=204&v=1sd26pWhfmg
HN user
ramimac
Security, for the Internet, at Wiz
https://ramimac.me
We haven't blogged this yet, but a variety of teams found this in parallel.
The packages are quarantined by PyPi
Follow the overall incident: https://ramimac.me/teampcp/#phase-10
Aikido/Charlie with a very quick blog: https://www.aikido.dev/blog/telnyx-pypi-compromised-teampcp-...
ReversingLabs, JFrog also made parallel reports
It's a spam flood by the attacker to complicate information sharing[1]. They did the same thing in the Trivy discussion, with many of the same accounts.[2]
[1] https://ramimac.me/teampcp/#spam-flood-litellm [2] https://ramimac.me/teampcp/#discussion-flooded
Blood, sweat, and tears.
The investment compounds! I have enough context to quickly vet incoming information, then it's trivial to update a static site with a new blurb
This is tied to the TeamPCP activity over the last few weeks. I've been responding, and keeping an up to date timeline. I hope it might help folks catch up and contextualize this incident:
Upon issue creation another workflow spins up three independent coding agents to analyze the finding.
I'm curious
1) what the current statistics are for consensus
2) how the agents may/may not perform independently
3) what the agent profiles are and how they differ (model, harness, prompt/persona, all three?)
Reach out if you'd like me to check - I did the same for the trigger.dev team in fact[1].
(personal site linked in bio, who links you onward to my linkedin)
[1] https://x.com/ramimacisabird/status/1994598075520749640?s=20
Probably, but you can check out a more robust list here: https://blog.cloudflare.com/tag/acquisitions/
* BastionZero
* Kivera
* Baselime
* PartyKit
* Area 1
* Vectrix
* Zaraz
* Linc
* S2 Systems Corporation
* Neumob
* Eager
* CryptoSeal
* StopTheHacker
Always a funny title, see previously: Announcing the New AWS Secret Region (2017) [1]
It's not a coincidence - this attack is directly downstream of s1ngularity
Hi! Author here who added the VSCode stat :)
I thought it was useful to include because:
* it can inform triage, if you use the extension you're more likely to be impacted * because it was VSCode, Workplace Trust actually partially mitigated this in at least 38 cases
I have evidence of at least 250 successes for the prompt. Claude definitely appears to have a higher rejection rate. Q also rejects fairly consistently (based on Claude, so that makes sense).
Context: I've been responding to this all day, and wrote https://www.wiz.io/blog/s1ngularity-supply-chain-attack
Thanks! Unfortunately, I've somehow fallen off the paved road :) https://github.com/ramimac/wiki/blob/main/CNAME
Fixed! Pages drops the custom domain whenever I push right now, have been putting off debugging it - apologies
In case it's helpful, I also collate quality blog posts in this genre over at https://rami.wiki/soc2/
It's not available in this case, or every case. When available, you can search "The data was provided by" in https://haveibeenpwned.com/PwnedWebsites
https://github.com/juliocesarfort/public-pentesting-reports is a substantial collection of public reports
Off the top of my head, DoyenSec has some good reports in there targeting web apps
Press Release version in case anyone gets paywalled: https://www.prnewswire.com/news-releases/iverfiy-discovers-s...
Not sure how the link got munged, but the root is https://docs.aws.amazon.com/securityhub/latest/userguide/gua...
It's definitely a bit of a simplification - although I'm not aware of large orgs using anything else to meet the relevant PCI requirement
The whitepaper AWS commissioned helping explain GuardDuty to auditors[1] is definitely a large component there
[1] https://d1.awsstatic.com/certifications/foregenix_amazon_gua...
GuardDuty does what AWS says it will do
What do you view as AWS' commitments around GuardDuty? I see pretty clear positioning by AWS of GuardDuty as a one-and-done solution for threat detection.
Top level marketing claims include:
* "Protect against ransomware and other types of malware" - which is why I looked at how viable GuardDuty would be against the most common form of S3 "ransomware"
* "Detect suspicious activity in your generative AI workloads" - but they don't actually have coverage of the vast majority of GenAI Services
* "Continuous monitoring across AWS accounts and workloads without added cost" - except the service is expensive (if worthwhile for the foundational data sources!) and has unpredictable costs
competing product/service
I see canary infrastructure as complimentary to Guardduty (w/ foundational data sources) - which is explicitly stated in the piece!
nb: I'm the author, in case it's non-obvious!
Agreed - I find the credential exfil alerts meaningful. I appreciate that AWS has invested in making them better in recent years (bypass details in https://hackingthe.cloud/aws/avoiding-detection/steal-keys-u...)!
I also find the DNS based cryptomining detections pretty handy, and high enough signal.
Great point on VPC Flow Logs! With the move to SKU off various GuardDuty features (S3 protection, Runtime, etc.) ... it'd be nice if GuardDuty monitoring of VPC Flow logs were more configurable
https://againsthimself.medium.com/security-engineering-proce...
A recently published commentary on Security Engineering would be a good supplement, naming the flaws seems a meaningful mitigation for them
Which cloud provider?
https://github.com/prowler-cloud/prowler is easy to get going with, and gives decent results. It's much stronger at AWS than GCP or Azure.
Steampipe can be a little harder to wrap your head around, but scales really well and has broader support: https://hub.steampipe.io/mods?objectives=security
There is a lot of advice in this thread that doesn't actually address your circumstances, or is just bad.
I recommend reading: 1. https://devd.me/log/posts/startup-security/ - relatively short and prescriptive 2. http://scrty.io/ - start with http://scrty.io/foundations + https://medium.com/starting-up-security/you-dont-need-a-chie... + https://medium.com/starting-up-security/starting-up-security...
How would you compare your offering to https://github.com/iann0036/iamlive (an opensource implementation of IAM generation from client-side monitoring or proxy, released in Feb 2021)?
Start with tldrsec.com - then accumulate blogs from the included links
I've enjoyed patio11's thoughts on this:
https://news.ycombinator.com/item?id=21908638 and https://twitter.com/patio11/status/1211406333653798913
I see the value just from a search perspective -- take as an example:
* I'm looking to stay 8 days in Paris in fairly peak season
* There is no good availability for a single Airbnb for 8 days
* This lets me see good matches of "3 in spot one, 5 in spot two" as well as "4 and 4" etc. without needing to do a lot of filtering by availability and digging into individual listings