The Rust Foundation has appointed Jacob Finkelman, a longtime Cargo team member, as its AI Security Engineer in Residence. Funded by Alpha-Omega, the role filters AI-generated vulnerability reports to ease maintainer burden while addressing supply-chain risks in the crate dependency graph. The six-month position builds on years of security tooling and parallels efforts in other languages.
Justin O'Leary reported a critical GCP IAM bypass in Config Connector. Google initially praised the find with "Nice catch!" and marked it high severity, but later denied a bounty claiming it was intended behavior. The flaw remains unpatched months later, exposing organizations to easy privilege escalation.
|