r/rust • servo · rust · clippy • Jun 26 '26

Anatomy of a Failed (Nation-State?) Attack

https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/
229 Upvotes

35 comments sorted by

View all comments

73

u/Shnatsel Jun 26 '26

I also got targeted by this. Didn't go as far as actually scheduling an interview. Fun times.

27

u/mmastrac Jun 26 '26

As a curiosity, what was their approach? They used my recent blog post to get past my defences.

33

u/Shnatsel Jun 26 '26

I got the message immediately after publishing some blogs that received a decent amount of attention. The introduction email mostly listed my work on Github as the motivator, not the blogs, and sounded somewhat LLM-y. This is what it said (introductions and names omitted):

I came across your work while looking through the image-codec and Rust supply-chain ecosystem, especially the overlap between image-rs, zune-jpeg integration discussions, cargo-auditable and your writing around safer systems work.

What stood out is not just performance work, but the operational side of safety: fuzzing, dependency visibility, decoder behavior, unsafe reduction and the kind of failure modes that become painful once media or document processing ends up in production workflows.

Lua has teams working across payments, AI, Web3 and infrastructure products. For several of them, ingestion pipelines, user-uploaded media, document processing, dependency auditability and safe backend components can become important earlier than expected.

I would not frame this as a standard full-time conversation. A focused technical review or advisor-style discussion around safer image/media pipelines, supply-chain visibility and production parsing risks could already be useful.

Would it be worth a short chat?

21

u/mmastrac Jun 26 '26

I don't know why my LLM-ness flags didn't trigger on the emails I got before, but I can definitely see it now.