慣性聚合 高效追讀感興趣之博客、新聞、科技資訊
閱原文 以慣性聚合開啟

推薦訂閱源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
量子位
M
Microsoft Research Blog - Microsoft Research
Microsoft Azure Blog
Microsoft Azure Blog
Jina AI
Jina AI
罗磊的独立博客
V
Visual Studio Blog
Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
aimingoo的专栏
aimingoo的专栏
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
博客园 - 三生石上(FineUI控件)
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MongoDB | Blog
MongoDB | Blog
小众软件
小众软件
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog

DEV Community

Autonomous Agents Need Receipts, Not Just Reasoning What 3.9M powerlifting records tell us about competition strategy — an EDA with Python Dev.to Article Draft #13 Beyond the Context Window: How to Build a Self-Improving AI Agent with Persistent Memory Full Agentic Stack - 5 Ideias da Arquitetura 'AI-First' que Vão Mudar a Forma Como Você Desenvolve Software Daily Briefing Platform Banning Agent PRs Won't Save Open Source Hitting Merge: Mentally Preparing for Your First Push to Production Learning Progress Pt.17 Monitoring Containers on AWS ECS with CloudWatch Tier 4 — Entity and Authority: Wikidata, KG, sameAs threading LocalFind Gemma — AI-Powered Semantic Search and Chat for Your Local Files AI-dy: On-Device Emergency First Aid with Gemma 4 Datrix: Chat With Your Data Using Gemma 4 — Charts, ML Models, No Code Understanding Reinforcement Learning with Human Feedback Part 4: Teaching Models Human Preferences The Architect’s Pivot: Mastering Parallel Agent Orchestration with Antigravity 2.0 Quidditch - Powered By PostgreSQL and ASP.NET Build a Database Connection Framework In 133 Lines Of Code How I mapped 600+ GPS audio-guides as a solo dev (and why I finally did it after 8 years) Installing Terminal & WSL (Windows Subsystem for Linux) A Floating Productivity Panel I Built for Android The Microsecond Lie: Why your Go timers are lying about the GPU Google used 6,000 open-source contributors then locked the door. Classic. Terceira semana tentando voltar ao mercado de trabalho How I turned a Python function into a web app in one decorator I Got Tired of Heavy Design Tools… So I Built My Own 😩 The Google I/O 2026 Moment That Quietly Changed How I See AI Getting Started: Run Your First Local LLM in 5 Minutes Building a 1% Fee Web3 Marketplace for Study Notes: Is a 5% Shift Sustainable? Full Agentic Stack - 5 Ideias da Arquitetura 'AI-First' que Vão Mudar a Forma Como Você Desenvolve Software Build Club Week Four: the part of Themis Lex I never explained I Tried Google Antigravity 2.0 Here's What It Actually Feels Like to Code With AI Agents By Isaac Yakubu | Google I/O 2026 Challenge Submission The growth quest picks what you avoid, not what you're already good at Firebase AI Logic's Template-Only Mode Is the Security Feature We Actually Needed Hardware Guide: What Do You Actually Need to Run Local LLMs? Constitutional Exception Committees: A Pattern for AI Agent Constraint Governance Veltrix's Treasure Hunt Engine: Optimized for Long-Term Survival, Not Just Scalability Open WebUI: Your Local ChatGPT Build a streaming UI without overcomplicating it The Cost of Kernel CVE Patching Frequency in SLA Commitments Gemma 4 Runs on a Raspberry Pi. Let That Sink In. The Git Filesystem - Recreating the Content-Addressable Database Why I Still Believe Our Event-Driven Architecture Was The Right Call For Veltrix Local RAG: Chat With Your Documents (Open Source, Private) GGUF & Modelfile: The Power User's Guide to Local LLMs What Excited Me Most at Google I/O 2026 OSS assemble! Kilo Code is launching on Product Hunt. Join the launch! https://www.producthunt.com/products/kilocode Your Organizational AI Adoption Metrics Are Lying (Plus How to Measure Real Adoption) Building a Production-Grade MLOps Home Lab on Windows — K8s, LLM, RAG & GitLab CI The Moment I Realized AI Agents are Changing Software Forever
供应链攻击+陈旧凭证:何故此组合于二零二六年尤显凶险
Ali-Funk · 2026-05-24 · via DEV Community

GitHub及Grafana Labs近事,显今之基构之痛:纵有坚防,若疏于凭信之管理,亦能尽溃。

何事之有?

以受侵之TanStack npm包为道,链路之攻,致逾三千八百内GitHub仓库为恶VS Code插件所破。未几,Grafana Labs告白,攻者窃其源码,盖因急更令中遗一GitHub令牌也。

二事殊异,其本同。

其核之训

人之记性,非安身立命之策也.
吾八载躬耕于IT之基构与治理,睹此弊习,屡见不鲜。众团队重金筑防火墙,分域而治,察敌于微,然于凭信之洁,尤重轮换密钥与权责之限——此二者,常视作余事.

何故此二者合之,凶险若此

供链之攻遇陈旧凭据,其患倍增。

  • 攻者毋须再破密码矣。彼但恃既有之信符而肆虐。

  • 一失令牌于更迭,则敌可长窥要务之系。

  • 受侵依赖(如 npm 包或 VS Code 扩展)乃无声之入口。

此非空谈,乃云原生与DevOps繁重之新常也。

二零二六年实用之策

欲御此患,诸组织须自被动修补,迁为架构之坚韧:

施行自动化密钥轮换

凭据宜设默认之期。自动化可去人误于算。

  1. 严守最小权限
  2. CI/CD令牌与服务账户,当仅授其必要之权,毋得逾越
  3. 视每一第三方依赖为不可信之物
  4. npm包、VS Code插件及其他工具,须持续扫描监察,此乃常制
  5. 制系统,当能容人失之误
  6. 假令凭信终泄。

当构架构,强于区隔,适时取用,速察异行。

终思

二二六年,强卫非独御外患而已。

乃在构系,能存难避之失,兼容人误。

供应链之攻与陈旧凭据之弊,尤甚凶险,盖因其既利用生态之信,复乘己程之隙也。

今尔之众如何应对密钥轮换与供应链安全乎?

出处:

BleepingComputer(哔哩哔哩电脑)
GitHub 确认遭恶意 VS Code 扩展入侵,影响 3,800 仓库
https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/

BleepingComputer:Grafana言失窃GitHub之令,使盗者得窃代码之库
https://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/

The Hacker News / Unit 42:TanStack npm供应链之攻分析
https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/