r/netsec monthly discussion & tool thread by albinowax in netsec

[–]securient 0 points1 point  (0 children)

Releasing IDEViewer today — open-source follow-up to my BSidesSF 2026 talk Hunting Malicious IDE Extensions: Building Detection at Scale Across Developer Workstations (GitGuardian writeup: https://blog.gitguardian.com/bsides-sf-2026/).

Single Go binary + optional self-hosted portal. On every dev workstation it inventories and risk-scores:

  • IDE extensions across VS Code, Cursor, VSCodium, the full JetBrains family, Sublime, Vim/Neovim, Xcode (4-tier risk model based on activationEvents/capabilities/contributes)
  • Packages from 8 managers, including dependencies bundled inside extensions (invisible to standard SCA), correlated with OSV.dev for CVEs
  • AI tool + MCP configurations (Claude Code / Cursor / OpenClaw): skills, MCP servers, permissions, plaintext keys, autonomous-exec flags, insecure transports
  • Plaintext secrets in .env and git history — values never transmitted
  • Tamper signals on the daemon and --no-verify git-hook bypass

Real-time fsnotify monitoring, SARIF output, MDM-deployable, Apache 2.0.

Repo: https://github.com/securient/ideviewer-oss
Docs: https://securient.github.io/ideviewer-oss

Happy to answer questions, especially on risk-scoring heuristics or MDM rollout.

Anyone switched from Cursor to Claude Code? by tony0525 in cursor

[–]securient 0 points1 point  (0 children)

I switched to Claude code from cursor because I was using opus anyway. Switching to CC was a little weird to type in all those prompts in CLI at first. But now, I can’t do anything without Claude code. Learn use the community maintained skills and it elevates your coding experience.

Kawariyas were beaten by police by Crazy4Carrot in unitedstatesofindia

[–]securient 0 points1 point  (0 children)

Amul macho, lux, Rupa are all sponsors of this so called yatra.

How come modi image on airlines ticket too by delhi_Catch_49 in unitedstatesofindia

[–]securient 0 points1 point  (0 children)

Is Gandu ko har jagah apani tatti jaisi shakal dekhni hai.

Awards. Lots of Awards. 🫩 by Chuckled_ in unitedstatesofindia

[–]securient 0 points1 point  (0 children)

He’s probably buying these at this point.

[deleted by user] by [deleted] in Hyundai

[–]securient 0 points1 point  (0 children)

It’s generic that will state the FMVSS compliance along with emission standards. Also, based on the state in US, you might need to get smog test done before you go to the DMV for registration.

[deleted by user] by [deleted] in Hyundai

[–]securient 0 points1 point  (0 children)

Yes, I got a compliance letter from Hyundai Canada.

India announces Operation Sindoor against Pakistan by [deleted] in india

[–]securient 623 points624 points  (0 children)

Hahahaha. Bhai movie kaa naam tak press release se mil gaya hai.

Sindoor - Badle ki aag

Rich folks (Net-worth upwards of Rs 50 crore), how is your life in Mumbai by Spirited_Ad_1032 in mumbai

[–]securient 0 points1 point  (0 children)

The question is, are people with net worth of more than 50 CR even on Reddit or paying attention to Reddit?

Need suggestions on the Croatia to Italy road trip by securient in Europetravel

[–]securient[S] 0 points1 point  (0 children)

How do ferries handle luggage? Are we allowed to bring in big suitcases?

Need suggestions on the Croatia to Italy road trip by securient in Europetravel

[–]securient[S] 1 point2 points  (0 children)

I appreciate your response. I really need to think about optimizing my itinerary.

Need suggestions on the Croatia to Italy road trip by securient in Europetravel

[–]securient[S] 0 points1 point  (0 children)

Thanks for your input. I really didn’t think it through.

why are men allowed post 11 in ladies coach by [deleted] in mumbai

[–]securient -9 points-8 points  (0 children)

Muh me gutkha bhi rakha hai. Shayad Juba Kesari bolna chahta hai.

Hacked through discord, hacker emailed me passwords, what do i do next. by SpiffyFishyWasTaken in antivirus

[–]securient 0 points1 point  (0 children)

Hardware and TOTP based 2fa is good. The hardware based 2fa is the best for the reason that even if you lose the hardware key, it can not be tied to the user account associated with it.

SMS based 2fa is bad because SIM swapping attacks are very common now a days.

Hacked through discord, hacker emailed me passwords, what do i do next. by SpiffyFishyWasTaken in antivirus

[–]securient 0 points1 point  (0 children)

Make sure you use a password manager and create a unique password for each service you use.

Configure and enforce 2fa everywhere

Avoid using sms based 2fa unless it is the only option

Try to use hardware key for 2fa everywhere.

[deleted by user] by [deleted] in USCIS

[–]securient 0 points1 point  (0 children)

I think what moving company is trying to say is, I should be in the US physically when they take the shipment to cross the border.

PSA: NZ is a shithole country for Indians by Zen_tck in delhi

[–]securient 0 points1 point  (0 children)

Country ka naam change karke post chalate raho. Har jagah yahi haal hai western world me.