"but where are all the bluesky instances?" i've heard this so many times that i wrote an explainer
There Are No Instances in atproto — overreacted
Like RSS and Google Reader.
overreacted.io
Paul
@ismisepaul.bsky.social
🔐 Product Security 📦 Software Supply Chain Security 🐍 Python 🧑💻 https://ismisepaul.github.io/
"but where are all the bluesky instances?" i've heard this so many times that i wrote an explainer
There Are No Instances in atproto — overreacted
Like RSS and Google Reader.
overreacted.io
#GitHub actions/checkout v7 in safer by default shocker! 🎉 > Safer fork pull request handling: checkout now refuses to check out fork pull request code by default when the workflow is triggered by `pull_request_target` or `workflow_run`. (tip: don't opt in) github.com/actions/chec...
GitHub - actions/checkout: Action for checking out a repo
Action for checking out a repo. Contribute to actions/checkout development by creating an account on GitHub.
github.com
This is what happens when you replace customer service with an AI chatbot: Instagram users getting hacked in the dumbest possible way. @jasonkoebler.bsky.social has more. Read now: www.404media.co/hackers-simp...
TanStack has published a post-mortem of its supply chain attack Blames hack on three vulnerabilities chained together, involving pull requests, GitHub actions, and OIDC tokens extracted from memory tanstack.com/blog/npm-sup...
Postmortem: TanStack npm supply-chain compromise | TanStack Blog
On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 mal...
tanstack.com
🚨 Supply chain attack: SAP CAP and Cloud MTA npm packages compromised to download and execute unverified binaries. Affected versions: → mbt@1.2.48 → @cap-js/db-service@2.10.1 → @cap-js/postgres@2.2.2 → @cap-js/sqlite@2.2.2 Details: socket.dev/blog/sap-cap...
SAP CAP npm Packages Hit by Supply Chain Attack - Socket
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environ...
socket.dev
This is an excellent summary of the US War on Iran current situation. I’m an existentialist and borderline absurdist and even I struggle with the current moment. This summary is just fantastic.
March, 19-21: God is a comedian
A stiff drink is recommended
no01.substack.com
As someone deep into MCP (hello, I am one of the Core Maintainers of the protocol), what Kelsey alludes to here is 🎯 MCP completely removes the need to care about underlying API shape. Intent is what matters in a universal adapter. Behind the scenes you can use SOAP/XML for all we care.
What I'm reading from the popularity of MCP is that standardizing on REST for APIs may have been a mistake. Intent based APIs, backed by a discovery and example usage mechanism, was the way to go. JSON-RPC seems to have provided the foundation for new protocols like MCP to close the gap.
Running Docker Hub pulls at scale? This post shows how to add a Sonatype-protected proxy to centralize policy checks, cache trusted images, and keep existing workflows intact. Learn how → https://bit.ly/4jQBm2g
Safer Docker Hub Pulls via a Sonatype-Protected Proxy | Docker
Learn from Docker experts to simplify and advance your app development and management with Docker. Stay up to date on Docker events and new version
docker.com
New EU Vulnerability Platform GCVE Goes Live, Reducing Reliance on Global Systems
EU Launches GCVE, A Decentralized Vulnerability Database
Europe launches GCVE, a decentralized EU vulnerability database designed to reduce reliance on CVE and strengthen digital sovereignty.
thecyberexpress.com
Comics peeps. I am finally clocking off from work tomorrow and doing my annual splurge on as many of the year's best titles as I can get my hands on. What've been your highlights of 2025? Ongoing weeklies, collected tpbs, one-off graphic novels, reissues, indies, whatever you've got.
Good resources documenting software supply chain incidents www.sonatype.com/resources/vu...
A Timeline of SSC Attacks, Curated by Sonatype
View the history of software supply chain attacks, open source components analyzed by Sonatype
sonatype.com
Version 1 of the OWASP AI testing guide just got published. I promise you, from my own experience, this will save you a lot of heartache. github.com/OWASP/www-pr...
Given Shai-Hulud comeback (hello SHA1-HULUD 👋) It is quite timely to share my up-to-date repository for modern npm security best practices against supply chain malware attacks:
GitHub - lirantal/npm-security-best-practices: Collection of npm package manager Security Best Practices
Collection of npm package manager Security Best Practices - lirantal/npm-security-best-practices
github.com
Shai-Hulud Returns: Over 300 NPM packages infected via fake Bun runtime within hours helixguard.ai/blog/malicio...
Troy Parrott's 96th-minute winner keeps Ireland's World Cup hopes alive! The 23-year-old's hat-trick earns his country victory and a spot in the play-offs, breaking Hungarian hearts in the process. Remarkable scenes in Budapest.
🚀 GitHub is making Actions more secure by default We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default. We’ve opened a discussion to gather feedback 👇 🔗 github.com/orgs/communi...
Towards a secure by default GitHub Actions · community · Discussion #179107
Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...
github.com
The release candidate of the OWASP Top 10 2025 has been released owasp.org/Top10/2025/0... The definitive release should be out on November 20th
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
owasp.org
There's some really big caveats to this. A thread.
New: Google says it has discovered at least 5 malware families that use AI to rewrite their code and generate new capabilities on the fly, suggesting AI-powered malware is finally starting to take off. cloud.google.com/blog/topics/... Report also has interesting stories about state actors' AI use.
Just prompt it they way you like. E.g with something like this: docs.vibe-coding-framework.com/document-tem...
Security-Focused Prompts | Vibe Coding Framework
docs.vibe-coding-framework.com
🚨 Open source supply chain attacks are exploding. Starting today, that ends. We’re releasing Socket Firewall — FREE, zero-config, CLI that blocks malware before it lands on your laptop or CI. Just run: npm i -g sfw sfw npm install lodash Works for: npm, yarn, pnpm, pip, uv, and cargo.
The press release is here: www.secretservice.gov/newsroom/rel... Some images are below:
The US Secret Service says it has dismantled 300+ SIM card servers in the NYC area that could have disrupted communications ahead of the UN General Assembly (Myles Miller/Bloomberg) Main Link | Techmeme Permalink
🚨 Update: The "Shai-Hulud" supply chain attack has expanded to nearly 500 trojanized npm packages, including several from CrowdStrike, all using the same malware first seen in Tinycolor. Full details and package list: socket.dev/blog/ongoing... #NodeJS #JavaScript
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages...
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Halud" supply chain attack that previously hit Tinycolor and dozen...
socket.dev
#NPM:The popular @ctrl/tinycolor package with over 2mln weekly downloads has been compromised alongside 40+ other NPM packages (including Crowdstirke packages!) in a sophisticated supply chain attack: #SoftwareSupplyChainSecurity 👇
ctrl/tinycolor and 40+ NPM Packages Compromised - StepSecurity
The popular @ctrl/tinycolor package with over 2 million weekly downloads has been compromised alongside 40+ other NPM packages in a sophisticated supply chain attack. The malware self-propagates across maintainer packages, harvests AWS/GCP/Azure credentials using TruffleHog, and establishes persistence through GitHub Actions backdoors - representing a major escalation in NPM ecosystem threats.
stepsecurity.io
Hi everyone. The 'next day' busy-ness has fully set in. Since I still haven't gotten any followup from npm regarding account actions taken, and given that I have now been approached by authorities, I will need to hold off on the post-mortem for a day or two. Sincerest apologies for the delay.
🚨URGENT: A series of popular packages maintained by qix have just been compromised. Compromised packages include: • has-ansi - 12 million weekly downloads - V6.0.1 • supports-hyperlinks - 19m weekly downloads - v4.1.1 • chalk-template - 3.9m weekly downlaods - V1.1.1
A cryptostealer malware was pushed to a number of npm packages including debug, chalk , and a number of utility packages as a result of the compromise of a single contributor. We published guidance for customers and non-customers for how to detect if you were affected: semgrep.dev/blog/2025/ch...