Developer Advocate @Snyksec | Prev @Microsoft @Disney | Web dev and app sec things. Here for community, fun and learning. Not for numbers or influencing you.

Joined January 2014
790 Photos and videos
Pinned Tweet
16 Dec 2024
FYI:🟦☁️ 👉 @clarkio.com
1
1
860
Brian Clark retweeted
Big banks aren't known for moving fast on new tech. With AI it's a different story. Some are even buying supercomputers to train their own internal models.
2
2
5
367
Brian Clark retweeted
May 23
Versions of - laravel-lang/lang - laravel-lang/http-statuses - laravel-lang/attributes - laravel-lang/actions have been published with malicious versions Packagist has unlisted the packages, but if you installed any of them between May 22–23, treat the environment as compromised
1
7
12
1,489
Your first instinct after getting hit by the TanStack npm attack is to revoke your GitHub token. Don't. The malware polls GitHub every 60 seconds. Gets a 401? It runs rm -rf ~/ Here's the right remediation order before you touch a single credential. youtu.be/YrwM2EFYrUY
1
1
393
Brian Clark retweeted
May 20
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
581
3,608
11,532
7,491,383
Brian Clark retweeted
A government contractor just leaked a ton of sensitive info including admin passwords for CISA's AWS GovCloud accounts - all to a public GitHub repo. CISA says they "hold our team members to the highest standards of integrity and operational awareness" Followed by evidence of them turning off basic GitHub defaults that would protect from publishing secrets. And dictionary passwords that were the name of the service the year.
8
36
184
18,705
Brian Clark retweeted
💥 Game changer for Web Development announced at GoogleIO- Modern Web Guidance! It’s expert-vetted skills for web development based on best practices of latest specs and APIs. It ensures your agent/coding harness doesn’t default to older and out of date patterns to build sites.
19
94
754
91,133
Brian Clark retweeted
May 19
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
1,667
5,303
25,402
13,829,735
The timing of this is perfect. I just had a scenario where having learned something on my own helped me catch a bad suggestion by AI...
1
286
AI wanted to copy node_modules between two stages in a Dockerfile. One where devDeps are needed and one they're not (production). I called this out and it of course replied with "You're right — I should walk that back."
110
Brian Clark retweeted
Looking forward to chatting with @_clarkio today! Happening in 5 hours. Come hang with us! youtube.com/live/nt8KvxQiGmM…
1
1
5
561
Any guesses on when the same happens at Anthropic, OpenAI, Cursor? I think it's gonna be in the next 2-3 months. github.blog/news-insights/co…
1
197

I think we've reached the tipping point of AI companies subsidizing our usage of models and tools...
1
2
263
1
90
I think we've reached the tipping point of AI companies subsidizing our usage of models and tools...
1
493
Brian Clark retweeted
AI bois be like:
123
543
7,408
297,432
Brian Clark retweeted
oh that bitwarden cli supply chain campaign? see how easily npq catches a bunch of issues there: - provenance regression - postinstall script - version recency $ npm install -g npq use npq ✨
2
1
10
1,140
Brian Clark retweeted
Over the past month, some of you reported Claude Code's quality had slipped. We investigated, and published a post-mortem on the three issues we found. All are fixed in v2.1.116 and we’ve reset usage limits for all subscribers.
1,916
2,588
39,785
6,471,675
Brian Clark retweeted
Looking forward to hanging with @_clarkio!
Just scheduled! @_clarkio joins @nickytonline April 28th at 1pm Eastern to discuss building securely with AI. 👀 youtube.com/watch?v=nt8KvxQi…
1
4
301