logoalt Hacker News

otterleytoday at 4:42 AM3 repliesview on HN

What do you base that on? Threat researchers (and their automated agents) will still keep analyzing new releases as soon as they’re published.


Replies

mike_hearntoday at 8:33 AM

Their analysis was triggered by open source projects upgrading en-masse and revealing a new anomalous endpoint, so, it does require some pioneers to take the arrows. They didn't spot the problem entirely via static analysis, although with hindsight they could have done (missing GitHub attestation).

show 1 reply
PunchyHamstertoday at 12:25 PM

The fact threat researchers and especially their automated agents are not all that good at their jobs

show 1 reply
staticassertiontoday at 11:01 AM

> What do you base that on?

The entire history of malware lol

show 1 reply