this post was submitted on 20 Oct 2025
15 points (100.0% liked)

Cybersecurity

8535 readers
76 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
top 2 comments
sorted by: hot top controversial new old
[โ€“] Rentlar@lemmy.ca 3 points 1 week ago

This is why I'm always against auto-updates, malicious packages can get in way too easily and silently.

[โ€“] eleijeep@piefed.social 1 points 1 week ago

My problem with this report is that the only source that BC links is the write-up by "Koi Security," whose URL is "koi.ai" and the write-up has a lot of markers of having been written by an LLM (slop).

The supply-chain worm isn't that far-fetched but without corroboration it's impossible to know how many of these details are real and how many were just statistically likely (hallucinated) according to the LLM. And there are a lot of complex features of this worm that just scream the favourite refrain of the LLM: "BUT WAIT! THERE'S MORE!"