Ultralytics AI model hijacked to infect thousands with cryptominer
bleepingcomputer.com
bleepingcomputer.com
Looks like they've since given the bot its own account but that experience definitely soured me on the company.
(Also, there's an MIT licensed implementation of "yolov9" here: https://github.com/WongKinYiu/YOLO . Affiliated with neither Redmond nor Ultralytics as far as I know.)
What is the possible justification for this? And did they just not do any oversight at all? Did no one notice the CEO was suddenly full of shit?
I knew from the formulaic response it was an LLM but had to fight with the other person to get them to see it. As soon as you see the question being repeated back at you in summary form as part of the answer it’s probably an LLM.
"gpt" is a more egregious example of using naming scheme to gather more attention than a substantial connection to the original.
however this is a simple price to pay for allowing open research without requiring to go through the conventional approval/clearance process.
I wonder how that's going to be resolved, of if Google will just do their usual and make it close to impossible to appeal and get unbanned.
Names are identifiers. Allowing identifiers to contain anything besides identifier characters merely opens new and weird attack vectors.
Hopefully that's an exploit path they'll close soon, if they've not done so already.
So technically, all environment variables are unsanitized and this was only the first problem in a list of bugs. This bug specifically used the "pull_request" event/action because it is automatically executed without any chance of stopping it, and was using details exposed via the pull requests head.ref.
Next up: git usernames and emails that use shellcode injection names, because github probably won't introduce sanitization to all variables/inputs now.
This is a prime example why you should never ever use a shell to log arbitrary data.
These protections (WAF for SQL/XSS, branch names for this) will never be enough. The code/logic must be secure, any additional layer is not enough since the actual target must be secured.
Developers will do it if its necessary, and it is. These situations are just proving it is necessary.
untyped strings, untyped strings everywhere
and they're directly executed, with untrusted user input templated in, with full release privileges
the entire thing is insane
to think pypa deprecated pgp offline signing for this...
The injected malware code came from the PR branch name, called by a Github action that was misconfigured.
Open source and popular doesn't necessarily mean safe.
Technically you can read the code source but no one does that and especially for each update.