you are viewing a single comment's thread
view the rest of the comments
[–] 9 points 11 months ago

It's like a one-and-a-half-page article that also comes in audio and video form, don't be lazy.

spoilerThey vibe coded a bash injection vulnerability in their devops code, which was used to gain access to the repo and push out a release with malicious code, which prompted any installed LLM wrappers like cursor to gather anything that looked like a configuration or text file in the infected machine and presumably leak them to the attacker.

  • source
  • parent