Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

StepSecurity
stepsecurity.io > blog > runtime-security-for-aws-codebuild-hosted-github-actions-runners

Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners

1+ week, 5+ day ago   (584+ words) That is the environment more and more teams are now pointing their GitHub Actions jobs at. AWS CodeBuild can register itself as a just-in-time GitHub Actions runner, so a job that used to run on ubuntu-latest runs inside your AWS…...

Google News
stepsecurity.io > blog > 7nohe-openapi-react-query-codegen-compromised-npm-publishing-workflow

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

2+ week, 1+ day ago   (602+ words) The attacker did not need a maintainer npm password or a long lived npm token. The repository accepted an npm publish comment from any pull request participant, checked out that pull request, installed its dependencies, and published packages with a…...

StepSecurity
stepsecurity.io > blog > arrayref-rust-crate-supply-chain-attack

Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat Execute a Remote Payload at Build Time

3+ week, 2+ day ago   (1076+ words) There is not a single line of malicious code inside arrayref itself, and that is exactly what makes this attack dangerous. The poisoned release changes nothing but its dependency manifest. The malicious crate, meanwhile, ships the genuine proc-macro2 source, so…...