Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 weeks ago

NPM flooded with malicious packages downloaded more than 86k times

https://arstechnica.com/security/2025/10/npm-flooded-with-malicious-packages-downloaded-more-than-86000-times/

#HackerNews #NPM #malicious #packages #security #vulnerabilities #cyber #threats #software #development

Ars Technica

NPM flooded with malicious packages downloaded more than 86,000 times

Packages downloaded from NPM can fetch dependancies from untrusted sites.
  • Copy link
  • Flag this post
  • Block
Dendrobatus Azureus
@Dendrobatus_Azureus@mastodon.bsd.cafe  ·  activity timestamp 3 weeks ago

It seems to be quite convenient that google flags immich.app site as dangerous, since immich is an environment in which you can host your own photographs in a safe manner without Google.

#Immich #app #self #hosting #technology #OpenSource #programming #Linux #photographs #Google #Malicious

https://immich.app/blog/google-flags-immich-as-dangerous

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
Michael Downey 🧢 boosted
h o ʍ l e t t
@homlett@mamot.fr  ·  activity timestamp 3 months ago

→ We Are Still Unable to Secure LLMs from #Malicious Inputs
https://www.schneier.com/blog/archives/2025/08/we-are-still-unable-to-secure-llms-from-malicious-inputs.html

“This kind of thing should make everybody stop and really think before deploying any AI agents. We simply don’t know to defend against these attacks. We have zero agentic AI systems that are secure against these attacks.”

“It’s an existential problem that, near as I can tell, most people developing these technologies are just pretending isn’t there.”

#AI#LLMs #stop #agents #secure #attacks #problem

  • Copy link
  • Flag this post
  • Block
h o ʍ l e t t
@homlett@mamot.fr  ·  activity timestamp 3 months ago

→ We Are Still Unable to Secure LLMs from #Malicious Inputs
https://www.schneier.com/blog/archives/2025/08/we-are-still-unable-to-secure-llms-from-malicious-inputs.html

“This kind of thing should make everybody stop and really think before deploying any AI agents. We simply don’t know to defend against these attacks. We have zero agentic AI systems that are secure against these attacks.”

“It’s an existential problem that, near as I can tell, most people developing these technologies are just pretending isn’t there.”

#AI#LLMs #stop #agents #secure #attacks #problem

  • Copy link
  • Flag this post
  • Block
Tyng-Ruey Chuang boosted
Gea-Suan Lin
@gslin@abpe.org  ·  activity timestamp 3 months ago
https://blog.gslin.org/archives/2025/08/16/12575/stardict-%e9%a0%90%e8%a8%ad%e6%9c%83%e5%b0%87%e5%89%aa%e8%b2%bc%e7%b0%bf%e7%9a%84%e5%85%a7%e5%ae%b9%e9%80%8f%e9%81%8e-http-%e4%b8%8d%e6%98%af-https-%e5%82%b3%e5%88%b0%e4%b8%ad%e5%9c%8b%e7%9a%84/

StarDict 預設會將剪貼簿的內容透過 HTTP (不是 HTTPS) 傳到中國的伺服器上

#china #chinese #clipboard #http #https #malicious #privacy #security #stardict

  • Copy link
  • Flag this post
  • Block
Gea-Suan Lin
@gslin@abpe.org  ·  activity timestamp 3 months ago
https://blog.gslin.org/archives/2025/08/16/12575/stardict-%e9%a0%90%e8%a8%ad%e6%9c%83%e5%b0%87%e5%89%aa%e8%b2%bc%e7%b0%bf%e7%9a%84%e5%85%a7%e5%ae%b9%e9%80%8f%e9%81%8e-http-%e4%b8%8d%e6%98%af-https-%e5%82%b3%e5%88%b0%e4%b8%ad%e5%9c%8b%e7%9a%84/

StarDict 預設會將剪貼簿的內容透過 HTTP (不是 HTTPS) 傳到中國的伺服器上

#china #chinese #clipboard #http #https #malicious #privacy #security #stardict

  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login