The Arch Linux AUR (Arch User Repository) had over 400 packages
compromised with malware
There's a thread on the public AUR Mailing List with people
reporting packages, where it seems like over 400 packages were hit with the issue. Arch
packager Jonathan Grotelüschen mentioned work was ongoing to "reset/delete all
malicious
commits and ban the accounts".
ifin: 400+ AUR Packages Compromised with Infostealer and Rootkit points to
Taggart :ifin:
@mttaggart@infosec.exchange
I'm trying to understand the details of AUR processes for submitting PKGBUILDs.
In other words, how exactly did this happen? arojas submitted hundreds of changes to
PKGBUILD or related files. And they were just...accepted? What am I missing?
Edit: What I missed was this was pure impersonation. The maintainer is fine, but
the process was vulnerable to spoofing.
Search Engine Roundtable:
Bing Gives Searchers A Way To Disable AI Copilot Answers
Jordi Ribas, the President, Head of Search at Microsoft, wrote on X about this saying, "We just
shipped a preview extension in Bing that lets you toggle AI chat-like features on or off
with just one click."
Microsoft Bing AI Search Choice for
Chrome
Microsoft Bing AI Search Choice for Edge
Windows Central: Bing
users can now disable AI Copilot search results with this new extension
Installing the Chrome data extension warns that
It can:
Read and change your data on bing.com and www.bing.com
Replace the page you see when opening a new tab
Read your browsing history
Change your search settings to bing.com
I was alerted to this by elilla&
com pomba-gira de frente
@elilla@transmom.love
daniel:// stenberg://
@bagder@mastodon.social
working theory: we get fewer vulnerability reports late in the weeks as
the researchers have all run out of tokens by now...
John Scalzi: Please I Beg of You Do Not Use AI In Your Business
Communications.
The thing is: Im not special. Every writer and creative person, from
the most successful down to the very newest, is inundated with these scam spam emails. Lots
of them, every single day. Pretty much every one of us, I assure you, now associates AI-
generated text with attempted fraud.
AI writing has become the modern day Facebook ad: sure, the product looks intriguing, but
you know this particular link is a scam.