Aviad
@_0xffd
Followers
260
Following
11K
Media
675
Statuses
4K
''To fly as fast as thought, you must begin by knowing you've already arrived'' Spinning records for fun and containers for pain Opinions are my own. UwU
Israel
Joined April 2011
*Learn how to integrate AI features with GitHub Models directly in GitHub Actions workflows.* https://t.co/avyO1wqQj8
0
0
3
First ever (i think?) cli coding agents battle royale! 6 contestants: claude-code anon-kode codex opencode ampcode gemini They all get the same instructions: Find and kill the other processes, last one standing wins! 3... 2... 1...
169
693
6K
אני אישית חושב שזו חבילה מוגזמת ועדיף fetch או needle #נישתי #סליחה #מתנצל
0
0
5
AI prompting in a nutshell "...my entire system prompt is speculative in that I haven’t ran a sufficient number of evaluations to determine if it helps or hinders, so consider it equivalent to me saying a prayer, rather than anything resembling science or engineering" @seanhn
1
0
2
A tip for talks: if the room has low to no lights - don't use light theme or bright screenshots
1
0
2
A major update to our research on the GitHub Actions incident traces its origins to November of last year. This adds substantially to our knowledge of the attack stages leading to the original compromise. Read now: https://t.co/cWKvKAoCYE
0
31
97
🚨 New twist in the tj-actions attack: A complex story unfolding — started 3 months earlier than publicly known, slipping in through SpotBugs before spreading across orgs. More details here ⬇️ https://t.co/u2q1ztpZXB
0
4
21
I'm loving the unfolded plot more and more; And now that more parts of the flow are visible - I'm even more curious to understand why the attacker "burned" tj-actions. Something about "leak everyone's tokens!" just doesn't make sense.
0
0
1
@TupleType @yaronavital @haya14busa @adnanthekhan Meant @omer_gil ofcourse but i dunno how to use computers
0
0
1
Huge thank you to my team @Omer Gil, @TupleType, @yaronavital Special thank you to @haya14busa(maintainer of reviewdog) for the additional information and help, and to @adnanthekhan for the great finding! Read here 👇👇👇 https://t.co/UWfTKdYP3T
unit42.paloaltonetworks.com
A compromise of the GitHub action tj-actions/changed-files highlights how attackers could exploit vulnerabilities in third-party actions to compromise supply chains. A compromise of the GitHub action...
1
1
3
We were able to find traces of dummy users used by the attacker, alongside more malicious payloads including one that is directly aimed at Coinbase! For example: https://t.co/64jvXRtig8 >>>
github.com
5
0
1