Hacker Newsnew | past | comments | ask | show | jobs | submit | fromlogin
Popular code generator for TanStack Query hit by supply chain worm (aikido.dev)
5 points by lbw1215 12 days ago | past | discuss
Shai-Hulud was the best thing to happen to supply chain security (aikido.dev)
1 point by di 14 days ago | past
Security assessment found open model near frontiers (aikido.dev)
2 points by vic_b 20 days ago | past
We burned 11.7B tokens to find the best cyber AI model (aikido.dev)
15 points by piotrgrabowski 21 days ago | past | 7 comments
The Aikido Machine: on-prem AI pentesting that never leaves your network (aikido.dev)
2 points by ultra2d 36 days ago | past
Keyv and friends compromised in active Shai-Hulud supply chain attack (aikido.dev)
251 points by cimi_ 38 days ago | past | 138 comments
Anthropic's Fever Dream: Claude's package that stole real keys (aikido.dev)
11 points by lschueller 39 days ago | past | 1 comment
RubyGems Supply Chain Attack (aikido.dev)
3 points by knappe 52 days ago | past
Aikido Code Audit (aikido.dev)
38 points by ilreb 83 days ago | past | 14 comments
Multiple JetBrains IDE plugins caught stealing AI keys (aikido.dev)
34 points by sschueller 86 days ago | past | 5 comments
Critical auth bypass vulnerability in phpBB (aikido.dev)
2 points by Tiberium 3 months ago | past | 1 comment
Red Hat NPM Packages Compromised to Spread a Credential-Stealing Worm (aikido.dev)
2 points by oidong1 3 months ago | past
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer (aikido.dev)
2 points by nullbio 3 months ago | past | 1 comment
Google API keys keep working after you delete them (aikido.dev)
3 points by dsr12 3 months ago | past
Google API keys will keep working after you delete them (aikido.dev)
4 points by berlianta 3 months ago | past
Microsoft's Durabletask Package on PyPI Compromised. Mini Shai Hulud (aikido.dev)
3 points by mjtk 3 months ago | past
Mini Shai-Hulud Is Back: NPM Worm Hits over 160 Packages, Including Mistral (aikido.dev)
2 points by cebert 4 months ago | past | 1 comment
NPM supply-chain attack is targeting the SAP developer ecosystem (aikido.dev)
1 point by raffael_de 4 months ago | past | 1 comment
GPT-Proxy Backdoor in NPM and PyPI Turns Servers into Chinese LLM Relays (aikido.dev)
4 points by lschueller 4 months ago | past
Axios vulnerability with CVSS 10 over stated? (aikido.dev)
1 point by oofbey 4 months ago | past | 1 comment
[dupe] Telnyx package compromised on PyPI (aikido.dev)
85 points by overflowy 5 months ago | past | 1 comment
TeamPCP deploys CanisterWorm on NPM following Trivy compromise (aikido.dev)
3 points by Shank 5 months ago | past
Glassworm is back: A new wave of invisible Unicode attacks hits repositories (aikido.dev)
303 points by robinhouston 6 months ago | past | 193 comments
I wrote Gitleaks, now I'm maintaining Betterleaks (aikido.dev)
15 points by zricethezav 6 months ago | past | 3 comments
Aikido launches infinite pentesting – Automated pentesting on every release (aikido.dev)
11 points by advocatemack 6 months ago | past
AI Agents discovered a cache deception bug affecting SvelteKit on Vercel (aikido.dev)
2 points by advocatemack 6 months ago | past
Fake Clawdbot VS Code Extension Installs ScreenConnect Rat (aikido.dev)
1 point by askl 7 months ago | past
Malicious PyPI Packages Spellcheckpy and Spellcheckerpy Deliver Python Rat (aikido.dev)
1 point by birdculture 7 months ago | past
Shai Hulud strikes again – The golden path (aikido.dev)
4 points by gpi 8 months ago | past
PromptPwnd: Prompt Injection Vulnerabilities in GitHub Actions Using AI Agents (aikido.dev)
2 points by devy 9 months ago | past | 1 comment

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: