home.social

#tiledesk — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #tiledesk, aggregated by home.social.

  1. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

    #Megalodon #Malware #TileDesk

  2. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

  3. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

    #Megalodon #Malware #TileDesk

  4. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

    #Megalodon #Malware #TileDesk

  5. So basically, all your CI/CD tokens are compromised if you pulled the poisoned version of Tiledesk, and it infects some of your other repos via CI/CD, but it ends there unless your stolen tokens sits around and is used to gain access to other things. But other than that, it doesn't continue to propagate does it?

    #Megalodon #Malware #TileDesk

  6. Can someone clarify how the malware spread?

    So it initially came from and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  7. Can someone clarify how the #Megalodon malware spread?

    So it initially came from #Tiledesk and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  8. Can someone clarify how the #Megalodon malware spread?

    So it initially came from #Tiledesk and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  9. Can someone clarify how the #Megalodon malware spread?

    So it initially came from #Tiledesk and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.

  10. Can someone clarify how the #Megalodon malware spread?

    So it initially came from #Tiledesk and anyone who pulled Tiledesk recently and caught the malware then caused it to spread further...?

    I'm not entirely clear on how it spread to other repositories, but it seems tokens were stolen along the way. Is the trigger only when other people have a specific CI/CD workflow and push to main/master? A bunch of the infected repos don't have any other recent changes so I'm unclear on the spread.