Developer Advocate @Snyksec | Prev @Microsoft @Disney | Web dev and app sec things. Here for community, fun and learning. Not for numbers or influencing you.

More here 👉
FYI:🟦☁️ 👉 @clarkio.com
1
2
930
Anyone else getting a sense for what generation someone is in by how often they use the word “literally”?
3
3
403
It was amazing being able to knock out 4 PRs while on a plane. Kick off a cloud agent task, go watch a show, get alerted things are done, review, merge, move on to the next one.
1
409
I’m really enjoying this workflow especially when I’m on the go but I’m disappointed to see that @OpenAI no longer supports it. Why did they change this?! Phone → choose code project → delegate task → cloud agent works independently → review results/PR from phone
2
1
498
Brian Clark retweeted
A package registry should not be picking winners
9
4
92
16,562
Brian Clark retweeted
If your Instagram is public, Meta just enrolled you in something you didn't agree to. Their new AI tool, Muse Image, lets anyone @-mention your Instagram handle in Meta AI and generate images using your face and photos. launched Tuesday. opt-in by default. no notification when it happens. → you won't be told when someone creates an AI image of you → opting out only stops future generation; anything already made stays live → there's no mechanism to remove images created before you opted out how to turn it off: Instagram → Profile → Menu (☰) → Sharing and Reuse → turn off Posts and Reels under "Allow people to reuse your content on Instagram and with AI features at Meta" note: the setting is still rolling out. if you don't see it yet, keep checking. if you want the strongest protection right now: go private.
74
1,932
5,330
1,494,877
Brian Clark retweeted
Big banks aren't known for moving fast on new tech. With AI it's a different story. Some are even buying supercomputers to train their own internal models.
2
2
5
382
Brian Clark retweeted
Versions of - laravel-lang/lang - laravel-lang/http-statuses - laravel-lang/attributes - laravel-lang/actions have been published with malicious versions Packagist has unlisted the packages, but if you installed any of them between May 22–23, treat the environment as compromised
1
7
12
1,518
Your first instinct after getting hit by the TanStack npm attack is to revoke your GitHub token. Don't. The malware polls GitHub every 60 seconds. Gets a 401? It runs rm -rf ~/ Here's the right remediation order before you touch a single credential. piped.video/YrwM2EFYrUY
1
2
407
Brian Clark retweeted
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
563
3,532
11,351
7,539,215
Brian Clark retweeted
A government contractor just leaked a ton of sensitive info including admin passwords for CISA's AWS GovCloud accounts - all to a public GitHub repo. CISA says they "hold our team members to the highest standards of integrity and operational awareness" Followed by evidence of them turning off basic GitHub defaults that would protect from publishing secrets. And dictionary passwords that were the name of the service + the year.
8
34
179
18,764
Brian Clark retweeted
💥 Game changer for Web Development announced at GoogleIO- Modern Web Guidance! It’s expert-vetted skills for web development based on best practices of latest specs and APIs. It ensures your agent/coding harness doesn’t default to older and out of date patterns to build sites.
19
93
751
92,356
Brian Clark retweeted
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
1,624
5,163
24,949
13,923,822
AI wanted to copy node_modules between two stages in a Dockerfile. One where devDeps are needed and one they're not (production). I called this out and it of course replied with "You're right — I should walk that back."
113
Here we go...
I think we've reached the tipping point of AI companies subsidizing our usage of models and tools...
1
2
265