what the hell is even happening
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A security-focused commentary on the current wave of supply chain attacks, particularly the Shy Hallude worm series compromising npm, PyPI, and Cargo package registries. The Tanstack compromise is highlighted as a case study, where a GitHub Actions pull_request_target workflow misconfiguration allowed attackers to steal a publish token and release a malicious signed package. Practical mitigations discussed include using package scanning services like Socket, sandboxing tools like any.run, and configuring package managers to refuse packages newer than one week. The video also covers a QEMU/KVM hypervisor escape vulnerability and argues that AI is accelerating both attack and defense capabilities, predicting a difficult 5-7 year period as attackers gain early advantage.
•10m watch time
46.3K Impressions4 Comments