New threat model for dev clone for CVE-2024-32002

View profile for Craig Chamberlain

Principal cybersecurity researcher / contributor at six startups with four exits. Former Elastic, Q1 Labs, Uptycs, Acquia, VMware. Working on a knowledge graph combining ML, AI and prediction to solve alert fatigue.

Here's a new threat model; dev clones a repo and the repo owner gets execution and persistence on the dev's endpoint. Example: CVE-2024-32002 yields RCE via git clone. Anomalous child procs for the git client (how many benign child procs can there be?) would be a possible detection / hunt https://lnkd.in/eT_uifEa

To view or add a comment, sign in

Explore topics