<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Brandon Pugh&#39;s Blog</title>
    <link>https://www.brandonpugh.com/tags/security/</link>
    <description>Recent content in Security on Brandon Pugh&#39;s Blog</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <lastBuildDate>Mon, 01 Dec 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://www.brandonpugh.com/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Our response to a recent security incident (Mixpanel)</title>
      <link>https://www.brandonpugh.com/links/our-response-to-a-recent-security-incident/</link>
      <pubDate>Mon, 01 Dec 2025 00:00:00 +0000</pubDate>
      <guid>https://www.brandonpugh.com/links/our-response-to-a-recent-security-incident/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://mixpanel.com/blog/sms-security-incident/&#34;&gt;Our response to a recent security incident&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The noteworthy thing about this news to me is how it can serve as an example of how &lt;em&gt;not&lt;/em&gt; to disclose a security incident.
The post is incredibly vague and doesn&amp;rsquo;t make clear what actually happened like what systems were exposed or how or the scale of the &amp;ldquo;incident&amp;rdquo;.
The most specific they get is &amp;ldquo;detected a smishing campaign&amp;rdquo;, which feels like an intentional use of jargon that doesn&amp;rsquo;t add much value&amp;hellip; why not just say &amp;ldquo;phishing&amp;rdquo; as it&amp;rsquo;s not that important that it was via SMS instead email especially since they don&amp;rsquo;t even say who the campaign targeted (internal or end users?).
They do mention they &amp;ldquo;Performed global password resets for all Mixpanel employees&amp;rdquo; which sounds like an attacker used social engineering to compromise employee credentials and exfiltrate user data.
That&amp;rsquo;s kinda the definition of a data breach yet they only refer to it as a vague &amp;ldquo;security incident&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;I think the most telling aspect, though, is the fact that &lt;a href=&#34;https://openai.com/index/mixpanel-incident/&#34;&gt;OpenAI&amp;rsquo;s response&lt;/a&gt; to the same incident has &lt;em&gt;more&lt;/em&gt; details than Mixpanel&amp;rsquo;s and was released the day &lt;em&gt;before&lt;/em&gt;.
Makes it seem like Mixpanel only made a public announcement because OpenAI forced them to.&lt;/p&gt;
&lt;p&gt;Also from OpenAI&amp;rsquo;s response:
&amp;ldquo;After reviewing this incident, OpenAI has terminated its use of Mixpanel.&amp;rdquo;&lt;/p&gt;

       &lt;hr&gt; &lt;p&gt;Thank you for keeping RSS alive. You&#39;re awesome.&lt;/p&gt; &lt;p&gt;&lt;a href=&#34;mailto:blogrss@bpugh.dev&#34;&gt;Reply by email&lt;/a&gt;&lt;/p&gt;
        &lt;img src=&quot;https://blog.bpugh.workers.dev/cdn/images?p=/links/our-response-to-a-recent-security-incident/feed&quot;&gt;
      </description>
    </item>
    
    <item>
      <title>Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks</title>
      <link>https://www.brandonpugh.com/links/over-100-vs-code-extensions-exposed-developers-to-hidden-supply-chain-risks/</link>
      <pubDate>Mon, 20 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://www.brandonpugh.com/links/over-100-vs-code-extensions-exposed-developers-to-hidden-supply-chain-risks/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://thehackernews.com/2025/10/over-100-vs-code-extensions-exposed.html?m=1&#34;&gt;Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;VS Code users are advised to limit the number of installed extensions, scrutinize extensions prior to downloading them, and weigh the pros and cons of enabling auto-updates&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This is the approach I&amp;rsquo;ve been taking and being more selective with what I install in general.
This also applies to browser extensions.&lt;/p&gt;

       &lt;hr&gt; &lt;p&gt;Thank you for keeping RSS alive. You&#39;re awesome.&lt;/p&gt; &lt;p&gt;&lt;a href=&#34;mailto:blogrss@bpugh.dev&#34;&gt;Reply by email&lt;/a&gt;&lt;/p&gt;
        &lt;img src=&quot;https://blog.bpugh.workers.dev/cdn/images?p=/links/over-100-vs-code-extensions-exposed-developers-to-hidden-supply-chain-risks/feed&quot;&gt;
      </description>
    </item>
    
    <item>
      <title>Security Alert | NX Compromised to Steal Wallets and Credentials</title>
      <link>https://www.brandonpugh.com/links/security-alert-nx-compromised-to-steal-wallets-and-credentials/</link>
      <pubDate>Mon, 01 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://www.brandonpugh.com/links/security-alert-nx-compromised-to-steal-wallets-and-credentials/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/&#34;&gt;Security Alert | NX Compromised to Steal Wallets and Credentials | Semgrep&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Another day, another supply chain compromise&amp;hellip;&lt;/p&gt;
&lt;p&gt;What&amp;rsquo;s interesting about this incident, aside from how popular Nx is, is the use of AI.&lt;/p&gt;
&lt;p&gt;First, the code that allowed Nx to be compromised was generated by Claude Code and reviewed by an AI bot.
You can see &lt;a href=&#34;https://github.com/nrwl/nx/pull/32458/files#diff-0f55b87380c49811ff502d3f6b33e35e26dd5c22a69880c4415f6438a9f73672R26-R38&#34;&gt;the PR that introduced the vulnerability&lt;/a&gt; was meant
to enforce PR titles follow convention, but it just takes the arbitrary text from the PR on the &lt;em&gt;public internet&lt;/em&gt; and throws it into bash without any sanitization.
So there&amp;rsquo;s a good chance it wasn&amp;rsquo;t actually reviewed by a person.
Secondly, the malware that was later run on devs&amp;rsquo; machines, tries to use tools like Claude Code to help it find secrets.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://pivot-to-ai.com/2025/08/29/vibe-coded-build-system-nx-gets-hacked-steals-vibe-coders-crypto/&#34;&gt;A more cynical take&lt;/a&gt;&lt;/p&gt;

       &lt;hr&gt; &lt;p&gt;Thank you for keeping RSS alive. You&#39;re awesome.&lt;/p&gt; &lt;p&gt;&lt;a href=&#34;mailto:blogrss@bpugh.dev&#34;&gt;Reply by email&lt;/a&gt;&lt;/p&gt;
        &lt;img src=&quot;https://blog.bpugh.workers.dev/cdn/images?p=/links/security-alert-nx-compromised-to-steal-wallets-and-credentials/feed&quot;&gt;
      </description>
    </item>
    
    <item>
      <title>Passkeys for Normal People</title>
      <link>https://www.brandonpugh.com/links/passkeys-for-normal-people/</link>
      <pubDate>Tue, 27 May 2025 00:00:00 +0000</pubDate>
      <guid>https://www.brandonpugh.com/links/passkeys-for-normal-people/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.troyhunt.com/passkeys-for-normal-people/&#34;&gt;Passkeys for Normal People&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This is a pretty good overview of the current state of passkeys with some nice examples of the various ways sites might implement them.&lt;/p&gt;

       &lt;hr&gt; &lt;p&gt;Thank you for keeping RSS alive. You&#39;re awesome.&lt;/p&gt; &lt;p&gt;&lt;a href=&#34;mailto:blogrss@bpugh.dev&#34;&gt;Reply by email&lt;/a&gt;&lt;/p&gt;
        &lt;img src=&quot;https://blog.bpugh.workers.dev/cdn/images?p=/links/passkeys-for-normal-people/feed&quot;&gt;
      </description>
    </item>
    
    <item>
      <title>Anyone can be scammed</title>
      <link>https://www.brandonpugh.com/blog/anyone-can-be-scammed/</link>
      <pubDate>Tue, 25 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://www.brandonpugh.com/blog/anyone-can-be-scammed/</guid>
      <description>&lt;p&gt;Even Troy Hunt (a well-known security researcher and creator of &lt;a href=&#34;https://haveibeenpwned.com/&#34;&gt;Have I Been Pwned&lt;/a&gt;) fell for a phishing email.&lt;br&gt;
He wrote all about it on his blog:
&lt;a href=&#34;https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/&#34;&gt;A Sneaky Phish Just Grabbed my Mailchimp Mailing List&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I found it a valuable read, not only for the lessons learned, but it&amp;rsquo;s also a reminder that it could have happened to any of us.
The email looks fairly well crafted and I appreciated his analysis of the factors that led to him falling victim.
It&amp;rsquo;s important to remember that even the most security-minded people can make mistakes and that security is hard.&lt;/p&gt;
&lt;p&gt;Honestly the most frustrating part of the story is the fact that Mailchimp doesn&amp;rsquo;t delete unsubscribed emails and even worse they give you no way to opt out of that — so a list owner would have to regularly go in an delete them manually&amp;hellip; and why do they store your IP address?? 😡&lt;/p&gt;
&lt;p&gt;I also thought it was sneaky that they generated an api key on his account. So in addition to updating login credentials remember to check for any recently added api keys.&lt;/p&gt;
&lt;p&gt;I hadn&amp;rsquo;t thought of this vector before, but it&amp;rsquo;s now one more reason why I prefer subscribing via RSS.&lt;/p&gt;
&lt;p&gt;P.S. ButtonDown has a nice &lt;a href=&#34;https://docs.buttondown.com/subscriber-cleanup&#34;&gt;Subscriber cleanup&lt;/a&gt; feature.&lt;/p&gt;

       &lt;hr&gt; &lt;p&gt;Thank you for keeping RSS alive. You&#39;re awesome.&lt;/p&gt; &lt;p&gt;&lt;a href=&#34;mailto:blogrss@bpugh.dev&#34;&gt;Reply by email&lt;/a&gt;&lt;/p&gt;
        &lt;img src=&quot;https://blog.bpugh.workers.dev/cdn/images?p=/blog/anyone-can-be-scammed/feed&quot;&gt;
      </description>
    </item>
    
    <item>
      <title>CSP `connect-src` directive</title>
      <link>https://www.brandonpugh.com/til/html/csp-connect-src/</link>
      <pubDate>Fri, 26 Jan 2024 00:00:00 +0000</pubDate>
      <guid>https://www.brandonpugh.com/til/html/csp-connect-src/</guid>
      <description>&lt;p&gt;Today I learned that there is a Content-Security-Policy (CSP) directive &lt;code&gt;connect-src&lt;/code&gt; that you can use to restrict all outgoing requests from your website to only the domains that you specify.&lt;/p&gt;
&lt;p&gt;This is a powerful mitigation against any kind of script injection attacks since no data can then be exfiltrated from your page.&lt;/p&gt;
&lt;p&gt;It applies to &lt;code&gt;XMLHttpRequest&lt;/code&gt; (AJAX), &lt;code&gt;WebSocket&lt;/code&gt;, &lt;code&gt;fetch()&lt;/code&gt;, &lt;code&gt;&amp;lt;a ping&amp;gt;&lt;/code&gt; or &lt;code&gt;EventSource&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;CSP is an HTTP response header for enhancing the security of a site and there are of course several other directives you might want to enable.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://content-security-policy.com/&#34;&gt;This is a handy reference&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;If you want to see a real-world comprehensive example, take a look at the &lt;a href=&#34;https://report-uri.com/home/analyse/https%3A%2F%2Fhaveibeenpwned.com%2F&#34;&gt;CSP header for haveibeenpwned.com&lt;/a&gt; (this links to &lt;a href=&#34;https://report-uri.com/home/analyse&#34;&gt;the csp analyser from report-uri&lt;/a&gt;).&lt;/p&gt;

       &lt;hr&gt; &lt;p&gt;Thank you for keeping RSS alive. You&#39;re awesome.&lt;/p&gt; &lt;p&gt;&lt;a href=&#34;mailto:blogrss@bpugh.dev&#34;&gt;Reply by email&lt;/a&gt;&lt;/p&gt;
        &lt;img src=&quot;https://blog.bpugh.workers.dev/cdn/images?p=/til/html/csp-connect-src/feed&quot;&gt;
      </description>
    </item>
    
  </channel>
</rss>