41554 blogs · [ { "id": "01a0878f-aad8-71bc-9599-6a87dc93cc89", "title": "Protected: Is it An Issue? TOCTOU to Prompt Injection in OpenAI’s Codex Cloud Code Review", "url": "https://johnstawinski.com/2026/07/31/is-it-an-issue-toctou-to-prompt-injection-in-openais-codex-cloud-code-review/", "published_at": "2026-07-31T18:17:30+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87dd320ffc", "title": "Repo-jacking Anthropic’s Claude Community Plugins (And the SHAs That Saved Them)", "url": "https://johnstawinski.com/2026/06/18/repo-jacking-anthropics-claude-community-plugins-and-the-shas-that-saved-them/", "published_at": "2026-06-18T22:18:10+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87dd48bc91", "title": "Trusting Claude With a Knife: Unauthorized Prompt Injection to RCE in Anthropic’s Claude Code Action", "url": "https://johnstawinski.com/2026/02/05/trusting-claude-with-a-knife-unauthorized-prompt-injection-to-rce-in-anthropics-claude-code-action/", "published_at": "2026-02-05T16:48:09+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87ddca5bd9", "title": "Agent of Chaos: Hijacking NodeJS’s Jenkins Agents", "url": "https://johnstawinski.com/2025/05/06/agent-of-chaos-hijacking-nodejss-jenkins-agents/", "published_at": "2025-05-06T19:49:03+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87de3de4f0", "title": "CodeQLEAKED – Public Secrets Exposure Leads to Supply Chain Attack on GitHub CodeQL", "url": "https://johnstawinski.com/2025/03/26/codeqleaked-public-secrets-exposure-leads-to-supply-chain-attack-on-github-codeql/", "published_at": "2025-03-26T19:47:08+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87de668b76", "title": "Living as a Digital Nomad in Innsbruck, Austria", "url": "https://johnstawinski.com/2024/11/29/living-as-a-digital-nomad-in-innsbruck-austria/", "published_at": "2024-11-29T20:42:19+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87df0836d3", "title": "Black Hat and DEF CON Preview: “Grand Theft Actions” or “Continuous Integration, Continuous Destruction”?", "url": "https://johnstawinski.com/2024/07/30/black-hat-and-def-con-preview-grand-theft-actions-or-continuous-integration-continuous-destruction/", "published_at": "2024-07-30T16:34:42+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87df2d5c60", "title": "Fixing Typos and Breaching Microsoft’s Perimeter ", "url": "https://johnstawinski.com/2024/04/15/fixing-typos-and-breaching-microsofts-perimeter/", "published_at": "2024-04-15T16:27:52+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87df46a5d4", "title": "Playing with Fire – How We Executed a Critical Supply Chain Attack on PyTorch", "url": "https://johnstawinski.com/2024/01/11/playing-with-fire-how-we-executed-a-critical-supply-chain-attack-on-pytorch/", "published_at": "2024-01-11T16:56:00+00:00" }, { "id": "01a0878f-aad8-71bc-9599-6a87df865e70", "title": "Worse than SolarWinds: Three Steps to  Hack Blockchains, GitHub, and ML through GitHub Actions", "url": "https://johnstawinski.com/2024/01/05/worse-than-solarwinds-three-steps-to-hack-blockchains-github-and-ml-through-github-actions/", "published_at": "2024-01-05T20:37:24+00:00" } ] posts Claim your blog
Back to johnstawinski.com
Blog · corpus.blog/blogs/johnstawinski.com/posts

johnstawinski.com

johnstawinski.com

2026

2025

2024