The web is becoming a minefield for autonomous AI. 🕸️🤖 Google DeepMind paper introduces the first systematic framework for AI Agent Traps/adversarial content designed to manipulate, deceive, and exploit visiting agents... 1/2
Ruggero Tonelli
@ruggero.bsky.social
Performance, Security & Automation at scale - OpenSource - Linux | 改善 | Head of Platforms|SRE @netquest
A supply chain attack targeting the widely used HTTP client Axios has introduced a malicious dependency into specific npm releases, including axios@1.14.1 and axios@0.30.4. buff.ly/DGx0GMx #sbom #security 3npm #node
Supply Chain Attack on Axios Pulls Malicious Dependency from...
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHu...
socket.dev
Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets socket.dev/blog/trivy-u... If you use(d) aquasecurity/trivy-action please take action. #security #sbom
Trivy Under Attack Again: Widespread GitHub Actions Tag Comp...
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.
buff.ly
HarmonicSecurity/claudit-sec: Security audit tool for #Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions. github.com/HarmonicSecu... #ai #security
GitHub - HarmonicSecurity/claudit-sec: Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions.
Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions. - HarmonicSecurity/c...
github.com
In case you read #security news only during the weekend: CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root | Qualys blog.qualys.com/vulnerabilit... since 2017 over 12.6 million #linux servers #debian #ubuntu #suse
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root | Qualys
Qualys TRU has discovered confused deputy vulnerabilities in AppArmor (named “CrackArmor”) that allow unprivileged users to bypass kernel protections, escalate to root, and break container isolation.…
blog.qualys.com
Rust's standard library on the #GPU www.vectorware.com/blog/rust-st... [...] "We are cleaning up our changes and preparing to #opensource them" #rust #performance 🦀
Is #StackOverflow dead? 2y old question answered by data. It was killed by #llms, by SO own rules, or by users' democracy? An @hackernews thread worth reading news.ycombinator.com/item?id=4648...
We’re closing an incredible year for coding #GenAI but 'Correctness-Congruence Gap' in #LLM-generated Infrastructure as Code (#IaC) is still an issue: LLMs often produce syntactically correct code that not aligned with the intended architectural design and #security requirements
A simple, yet brilliant idea. aikidosec/safe-chain "wraps around the npm cli, npx, yarn, pnpm, pnpx, bun, bunx, and pip to provide extra checks before installing new packages[...] preventing downloading or running the malware." Thank you @AikidoSecurity www.npmjs.com/package/@aik...
npmjs.com
Whisper Leak: a side-channel attack on Large Language Models arxiv.org/abs/2511.03675. #llm #ai #security
Trixter: A #Chaos Proxy for Simulating Network Faults biriukov.dev/posts/trixte...
Not an AWSome morning for the ones "living" in #AWS us-east-1 and the correlated regions. #awsdown #awsoutage
5 years since the last senior #SRE opening in our team. Lots of stuff have been archived since then but we still have some interesting challenges for #performance, #automation and #security motivated talents. And we're #AI friendly ...Are you in? buff.ly/h2IXb1i
Days ago @karpathy released #nanochat: "The best ChatGPT that $100 can buy." github.com/karpathy/nan... The real deal is not the price but the ~8000 lines of code: The entire pipeline from start to end with tokenization, pretraining, finetuning, evaluation, inference, and GUI. #ai
Apache Cloudberry (Incubating) [..] an advanced and mature #opensource Massively Parallel Processing (MPP) database, [..] built on [..] PostgreSQL kernel [..]. can serve as a #data warehouse and [..] large-scale analytics and AI/ML workloads. cloudberry.apache.org
Apache Cloudberry (Incubating) | Apache Cloudberry (Incubating)
Apache Cloudberry ships with PostgreSQL 14.4 as the kernel. It is 100% open source and helps you leverage the value of your data.
cloudberry.apache.org
Apache SeaTunnel: Multimodal, high-performance, distributed, massive #data integration tool [...] for Transaction DB, Cloud DB, SaaS, Binlog with SQL-like code or Drag & Drop. #performance #opensource buff.ly/cfZGPNn
Apache SeaTunnel | Apache SeaTunnel
APache SeaTunnel Logo
seatunnel.apache.org
When Oracle Drops the Ball: Why #MariaDB is the Future of the #MySQL World. An interesting take by @kajarno #opensource MariaDB.org
When Oracle Drops the Ball: Why MariaDB is the Future of the MySQL World - MariaDB.org
The news has circulated quietly in industry corners, but the implications are far too significant to brush aside: Oracle seems to have ended the Open Source era of MySQL. … Continue reading "When…
mariadb.org
OpenSSF warns that #opensource infrastructure doesn't run on thoughts and prayers. Foundations say billions of downloads rely on registries running on fumes – and someone's gotta pay the bills
OpenSSF to freeloaders: Open source infra isn't free
: Foundations say billions of downloads rely on registries running on fumes – and someone's gotta pay the bills
theregister.com
phoronix : PostgreSQL Turns To AVX-512 For CRC32 Computations: Up To 3x Faster (where supported) buff.ly/fSlCOAG [...] In addition to the recent optional IO_uring support for the #PostgreSQL database server on Linux and async I/O batch mode[...] #performance #opensource
GitHub - doxx/darkflare: DarkFlare Firewall Piercing (TCP over CDN) buff.ly/3DphmCR "A stealthy command line tool to create TCP-over-CDN(http) tunnels that keep your connections cozy and comfortable"
GitHub - doxx/darkflare: DarkFlare Firewall Piercing (TCP over CDN)
DarkFlare Firewall Piercing (TCP over CDN). Contribute to doxx/darkflare development by creating an account on GitHub.
buff.ly
CISA, FBI, nations warn of fast flux DNS threat • The Register buff.ly/y4JdM1s "Malicious cyber actors use #fastflux to obfuscate the locations of malicious servers " #cybersec
Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication
Five critical flaws in Ingress NGINX Controller expose 6,500+ clusters; update now to prevent unauthorized remote code execution.
buff.ly
The Biggest #SupplyChain Hack Of 2025: 6M Records For Sale Exfiltrated from #Oracle Cloud Affecting over 140k Tenants | CloudSEK cloudsek.com/blog/the-big... #ransomware
The Biggest Supply Chain Hack Of 2025: 6M Records For Sale Exfiltrated from Oracle Cloud Affecting over 140k Tenants | CloudSEK
CloudSEK uncovers a major breach targeting Oracle Cloud, with 6 million records exfiltrated via a suspected undisclosed vulnerability. Over 140,000 tenants are impacted, as the attacker demands ransom...
cloudsek.com
fosrl/pangolin: Tunneled Mesh Reverse Proxy Server with Identity and Access Control and Dashboard UI
GitHub - fosrl/pangolin: Tunneled Mesh Reverse Proxy Server with Identity and Access Control and Dashboard UI
Tunneled Mesh Reverse Proxy Server with Identity and Access Control and Dashboard UI - fosrl/pangolin
buff.ly
Valkey · Reducing application latency and lowering Cloud bill by setting up your client library
Valkey · Reducing application latency and lowering Cloud bill by setting up your client library
By implementing AZ affinity routing in Valkey and using GLIDE, you can achieve lower latency and cost savings by routing requests to replicas in the same AZ as the client.
buff.ly
Breaking news for the crab people 🚨 🦀 Ring, a widely used Rust cryptography library, is now unmaintained. 🔐 Security advisory: rustsec.org/advisories/R... ➡️ Details: github.com/briansmith/r... #rustlang #opensource #library #security #cryptography
RUSTSEC-2025-0007: ring: *ring* is unmaintained › RustSec Advisory Database
Security advisory database for Rust crates published through https://crates.io
rustsec.org
Amazon Web Services plugin | Steampipe Hub
Steampipe Hub
Query AWS with SQL! Open source CLI. No DB required.
buff.ly
spegel-org/spegel: Stateless cluster local OCI registry mirror.
GitHub - spegel-org/spegel: Stateless cluster local OCI registry mirror.
Stateless cluster local OCI registry mirror. Contribute to spegel-org/spegel development by creating an account on GitHub.
buff.ly