Reading up on Socket
2 deep · digging since may 25
- The End Of Open Source - Gal Ratner
The article argues that open-source security now relies on accidental human vigilance rather than automated defenses, as AI agents increasingly exploit unmaintained projects and supply chains.
- A hacker group is poisoning open source code at an unprecedented scale
TeamPCP has automated its supply chain attacks with the Mini Shai-Hulud worm, breaching GitHub, OpenAI, and hundreds of firms.