This is an entirely untrue news story.
A wild claim made by a fake ‘journalist’ on social media, and several prominent journalists have fallen for it, including at @thetimes
This is very niche but I will explain…
@Discoplomacy "This bypassed the usual protections for pull requests from unknown contributors because the workflow was triggered by a comment, not by the pull request itself. "
But when little old me raises it, it's just information. Because I'm not some fancy AI?
@adnanthekhan 😉
@jordanbhx Looks like they've tried to follow https://t.co/69CaxkKcPf design system but done it very poorly.
I have always just used - https://t.co/3TEUh1J7Bb
@adnanthekhan Ignoring the weird 'retired' image, @samccone will be pleased his 10 year old vulnerability report can be closed.
https://t.co/xmSeqstMKb
Looks like a massive GitHub Actions exploitation campaign going on. Example commit:
https://t.co/4yD1WGi69r
https://t.co/goJsDeJEPw
Automated mass commits. We are investigating this.
cc: @github@GitHubSecurity
🚨 Pep Guardiola to leave position as Manchester City manager at end of this season. 55yo Spaniard departing after trophy-laden decade & set to be replaced by Enzo Maresca. No official confirmation yet from #MCFC. W/ @SamLee@TheAthleticFC after @MailSport https://t.co/FMjZXxfuPq
Seamus Coleman – one of our greatest-ever servants and captains – has announced his proud Everton playing career spanning more than 17 years will come to an end when his contract expires next month.
Thank you for everything, Seamus. 💙
@DanNeidle "councils should do a better job catching those who don’t."
Oh no, now someone has a reason to give Oracle a ton of money to implement a highly complex solution to calculate how much council tax someone has to pay depending on how many days their boat has spent in a council area
@drhingram "most Brummies support their policies"
That's an interesting opinion considering out of 101 councillors 78 are not Reform. Which suggests that most Brummies, 77% of them, over three quarters, don't support their policies.
🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading.
Newly confirmed compromised artifacts:
@opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads)
mistralai: 2.4.6 on PyPI
guardrails-ai: 0.10.1 on PyPI
additional @squawk/* packages on npm
guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.pyz, writes it to /tmp/transformers.pyz, and runs it with python3 without integrity verification.
The git-tanstack.com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds
Regardless I just came to say hello :^)”
The page also linked to a YouTube video and you can probably guess which one.
@LewisJWarner@ITVCentral This is not a serious person.
Firstly the Commissioners would never allow it given the revenue it generates. Then they would have to battle DEFRA and any civil legal challenges.
There are also projects which have allocated funding from CAZ, contracts already signed etc.
@johnclancy "... West Midlands Pension Fund said it 'did not recognise the figures quoted' without elaborating ... "
The surplus figure from their own accounts? What?