Shady A.
@shadyshoha
Co-founder @nexus_gpt | Amateur Photographer
ID: 2936005738
http://gpt.nexus 21-12-2014 22:17:19
129 Tweet
83 Followers
299 Following
1Code just launched on Y Combinator 1Code - The open source control panel allowing teams to use AI coding agents
Starting a series where we write up interesting vulns our agent at Veria Labs finds: First up, 1-click RCE in Goose, Block's coding agent with 33k+ stars: verialabs.com/blog/securing-… Goose was vulnerable to CSWSH, allowing an attacker-controlled website to run arbitrary commands.
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios