Fortunately this machine wasn't anything important for me and there was no sensitive data to exfil beyond AI API keys. But I imagine there's other orgs that just got catastrophically, irrecoverably pwned.
What's your story?
(RCE context: https://news.ycombinator.com/item?id=46136026 )
All platforms can be exploited I guess, but I still wonder at the complexity of the platforms we now rely on and whether it’s justified.
Specific to security, keeping React 100% client-side keeps things simple: Don't trust the front-end.
My gut feeling is that we are going to be feeling the consequences of simultaneous enshittification of software, the mounting complexity of our systems, and AI enslopification combine to create far more vulnerabilities in the future. The only defence is to adopt simple systems and software.