Luke Hinds (@decodebytes) 's Twitter Profile
Luke Hinds

@decodebytes

No longer active here; find me on: bsky.app/profile/lukehi…

ID: 1362107565841211397

calendar_today17-02-2021 18:32:28

2,2K Tweet

3,3K Takipçi

732 Takip Edilen

Stacklok (@stacklokhq) 's Twitter Profile Photo

Attackers continue to abuse open source ecosystems as a vector to deliver malware. In this incident, at least 4 trojanized npm packages silently collected and exfiltrated users' cryptocurrency wallet secrets upon installation. Read Poppaea's analysis of this attack here:

Luke Hinds (@decodebytes) 's Twitter Profile Photo

So much malware and other nasty’s out there, but lucky for us we have the awesome Poppaea tracking it down and giving a run down post autopsy like below.

Stacklok (@stacklokhq) 's Twitter Profile Photo

Honored to be a Rising Star ⭐ in Forbes 2024 Cloud ☁️ 100. This list is impressive, and we’re excited to be part of the cloud’s future. 🎉 Grateful for the recognition Bessemer Forbes Salesforce Ventures The Cloud 100 bit.ly/4fsf2tv #Cloud100 #RisingStar

Honored to be a Rising Star ⭐ in Forbes 2024 Cloud ☁️ 100. This list is impressive, and we’re excited to be part of the cloud’s future. 🎉

Grateful for the recognition
<a href="/BessemerVP/">Bessemer</a> <a href="/Forbes/">Forbes</a> <a href="/SalesforceVC/">Salesforce Ventures</a>
<a href="/cloud100/">The Cloud 100</a>
bit.ly/4fsf2tv
#Cloud100 #RisingStar
sigstore (@projectsigstore) 's Twitter Profile Photo

TSC Member Bob Callaway and community chair Hayden from the Google OS Sec Team chatted with puerco on the Stacklok hosted 🌮 Securi-Taco Tuesdays 📺show. Lot's on sigstore and & software supply chain security. Catch it here: youtube.com/watch?v=JwfTCe…

Luke Hinds (@decodebytes) 's Twitter Profile Photo

Another nasty one picked up by trustypkg. This one was quite interesting, as it had a Go binary baked in. One interesting obs, some well established (will remain nameless) infosec vendor DBs were showing this with 90+ scores for 'software supply chain' 🫣stacklok.com/blog/cross-pla…

sigstore (@projectsigstore) 's Twitter Profile Photo

The CFP deadline for SigstoreCon has been extended to Wednesday, September 18, 2024 at 11:59 pm Mountain Daylight Time (UTC-6). events.linuxfoundation.org/sigstorecon-su…

Stacklok (@stacklokhq) 's Twitter Profile Photo

In London? Our CTO Luke Hinds will be keynoting DevSecOps London Gathering tonight with a talk on "Secure Repo Management as Scale, with Minder" at Google's (Central Saint Giles) London Office. Sign up here👇 meetup.com/devsecops-lond…

In London? Our CTO <a href="/decodebytes/">Luke Hinds</a> will be keynoting <a href="/DevSecOpsLG/">DevSecOps London Gathering</a> tonight with a talk on "Secure Repo Management as Scale, with Minder" at Google's (Central Saint Giles) London Office. 
Sign up here👇
meetup.com/devsecops-lond…
Luke Hinds (@decodebytes) 's Twitter Profile Photo

Bandit is now more capable of scanning AI models. v1.7.10 flags insecure use of torch.load where untrusted data can lead to arbitrary code execution, and improper use of torch.save might expose sensitive data or lead to data corruption: github.com/PyCQA/bandit/r…

OpenSSF (@openssf) 's Twitter Profile Photo

🎉 Welcome to the OpenSSF family, Minder! 📣 Stacklok is contributing Minder to OpenSSF as a sandbox project! Minder streamlines #OSSSecurity, auto-remediates issues, and flags key risks for devs & security teams. 🔍 Learn more about Minder: openssf.org/guest-blog/202…

🎉 Welcome to the OpenSSF family, Minder! 
📣 <a href="/StackLokHQ/">Stacklok</a> is contributing Minder to OpenSSF as a sandbox project! Minder streamlines #OSSSecurity, auto-remediates issues, and flags key risks for devs &amp; security teams. 
🔍 Learn more about Minder: openssf.org/guest-blog/202…
Luke Hinds (@decodebytes) 's Twitter Profile Photo

At Stacklok we released codegate today, an open-source, privacy-focused local proxy that acts as an essential layer of security within a developers generative AI workflow. Support is available for copilot and Continue with others on the way github.com/stacklok/codeg…

Continue (@continuedev) 's Twitter Profile Photo

🔒Today Stacklok introduced CodeGate —local, open source privacy controls that work with your AI code assistant. You deploy a single container locally that encrypts secrets before they find their way into your prompts and alerts you when dangerous dependencies are suggested

The New Stack (@thenewstack) 's Twitter Profile Photo

Artificial intelligence is redefining industries at a staggering pace, and the field of cybersecurity is no exception. Luke Hinds @stacklokhq