Skip to content

intel: devsecops/compliance social updates 2026-03-25#6

Open
kamalsrini wants to merge 1 commit into
mainfrom
intel/devsecops-compliance-social-2026-03-25
Open

intel: devsecops/compliance social updates 2026-03-25#6
kamalsrini wants to merge 1 commit into
mainfrom
intel/devsecops-compliance-social-2026-03-25

Conversation

@kamalsrini

Copy link
Copy Markdown
Contributor

Automated skill updates from social intelligence scan (2026-03-25).

Findings Applied

  • H&R Block TLS Backdoor (HN #47457162, 149pts) — embedded wildcard root CA private key in DLL

Skills Updated

  • devsecops/secrets-management — embedded binary private key pattern (CWE-321)
  • appsec/secure-code-review — CWE-321/CWE-312 checklist items for CA/cert material
  • compliance/pci-dss-review — trusted-root manipulation case study (Req 4.2, 12.3)

Source

socialsecurityplan.md — 2026-03-25
HN: https://news.ycombinator.com/item?id=47457162

⚠️ Human review required before merge.

…26-03-25

- secrets-management: add embedded binary private key / root CA pattern (CWE-321)
- secure-code-review: add CWE-321/CWE-312 checklist items for CA/cert material
- pci-dss-review: add trusted-root manipulation case study under Req 4.2/12.3

Source: HN 47457162 — H&R Block TLS backdoor (embedded wildcard root CA in DLL)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
zeroknowledge0x added a commit to zeroknowledge0x/SecuritySkills that referenced this pull request Jun 18, 2026
…cle model

- Remove duplicated 'Indefinite (no expiry)' and 'Compensated risk misclassified as FP' lines in output
- Suppression lifecycle model with risk tiers, drift gates, and evidence requirements
- Enforce FP vs compensated-risk disambiguation throughout
- Add drift evidence gates: plugin update, exposure change, package change, control removal
- Common pitfalls UnitOneAI#6 (indefinite suppressions) and UnitOneAI#7 (compensated-as-FP)

Closes UnitOneAI#2724
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant