Kelly Shortridge

@shortridge.bsky.social

software resilience, cybersecurity, complex systems | chief product officer @fastly.com | nyc “In the information society, nobody thinks. We expected to banish paper, but we actually banished thought.” kellyshortridge.com @swagitda_ on Twitter

kaibo (multi-model subagents for your agent with safe shell powers) binaries are signed now. grab a binary, add it to your agent as a stdio mcp, use its /configure prompt to do the rest. containers next, then it gets a proper release. please let me know if it works github.com/tobert/kaibo...

Release v0.2.0-rc.3 · tobert/kaibo

What's Changed fix(release): bundle-only blob signature — cosign v3 ignores the legacy pair (rc.2 kink) by @tobert in #70 Full Changelog: v0.2.0-rc.2...v0.2.0-rc.3

github.com

every time I say this, someone didn't know: you can get the NYRB, the New Yorker, the LRB, Paris Review, The Spectator (weirdly not New Statesman), The Week, both French & Italian Vogue & New Scientist among many many other magazines FREE via the Libby app from your local library?

I love looking at old crazy ideas in expired computer patents. Modern CPU Branch Predictors are invisible. You, as a dev, can’t really see *what* paths the CPU is guessing…it’s all a bunch of AMD/Intel/Apple secret sauce. For a brief moment in the 80s, there was this wacky proposition of...

BildBild

In addition to all of the other benefits already reported about NYC congestion pricing, "In the first six months of the program, air pollution – in the form of particulate matter 2.5 micrometers and smaller – dropped by 22% in the Congestion Relief Zone (CRZ)" news.cornell.edu/stories/2025...

Congestion pricing improved air quality in NYC and suburbs | Cornell Chronicle

Cornell researchers tallied the environmental benefits of New York City’s congestion pricing program and found air pollution dropped by 22% in Manhattan, with additional declines across the city’s fiv...

news.cornell.edu

🚨 React2Shell Update: Fastly saw a 2,775% spike in attack traffic after the public PoC dropped. Attackers are actively scanning — verify exposure and patch now. Updates: • Expanded Virtual Patch • NGWAF detecting new scanners • Bot Management flagging tooling More intel to come. #React2Shell

Bild

⚠️ Friday’s #React2Shell update @fastly.com saw a 2,775% increase in attack activity across our global network between the peak we reported yesterday (Dec. 4th) and 20:00 UTC today (see graph). We recommend you immediately patch vulnerable apps and apply proactive protections to buy time as needed.

Kelly Shortridge@shortridge.bsky.social · 8mo ago

⚠️ update on #React2Shell After the POC dropped ~21:04 GMT today, Fastly detected a profound proliferation in the # of requests triggering our NGWAF signal for React2Shell (see graph). We strongly recommend you immediately identify and update your React / Next.js apps + apply proactive protection.

⚠️ update on #React2Shell After the POC dropped ~21:04 GMT today, Fastly detected a profound proliferation in the # of requests triggering our NGWAF signal for React2Shell (see graph). We strongly recommend you immediately identify and update your React / Next.js apps + apply proactive protection.

Area chart displaying hourly volume of requests triggering Fastly's NGWAF signals for CVEs 2025-55182 & 2025-66478. The chart shows no signals prior to 7pm GMT, a small spike between 7-9pm GMT, followed by a spike at 10pm GMT, and a massive spike at 11pm GMT.
Kelly Shortridge@shortridge.bsky.social · 8mo ago

There’s a react2shell POC circulating that appears to be viable. Fastly verified our NGWAF successfully blocks this exploit variant. ⚠️ Our initial data points suggest attackers are actively probing for vulnerable apps. ⚠️ Identify and update your React & Next.js apps + layer proactive protection.

There’s a react2shell POC circulating that appears to be viable. Fastly verified our NGWAF successfully blocks this exploit variant. ⚠️ Our initial data points suggest attackers are actively probing for vulnerable apps. ⚠️ Identify and update your React & Next.js apps + layer proactive protection.

the bad news: lots of sloppity slop PoCs (slopocs???) abounding for the critical pre-auth React RCE the good news: more time for you to patch your #React & #Nextjs apps ✨ my write up from yesterday on what to know & what to do: www.fastly.com/blog/fastlys...

Fastly’s Proactive Protection for Critical React RCE CVE-2025-55182 and CVE-2025-66478 | Fastly

Protect your apps from the critical React RCE bugs (CVE-2025-55182/66478). Fastly's NGWAF Virtual Patch provides proactive defense.

fastly.com

last week i remembered that macOS lets you set your own icons and that *I* have the power to delegitimize the professionalism of the software that runs on my machine, so here's a thread of the 16 new icons i've made so far i really forgot how fun it was to just sit down and make art for myself :')

comparison between apple's finder icon and mine. apple's is the split blue and white smiley face, mine is two blue and white anime girls making outcomparison between discord's icon and mine. mine is like a screaming cat on a blue/purple slimy backgroundcomparison between celsys's clip studio paint icon and mine. mine is similar but rotated with some comic styling and pink and blue highlightscomparison between mozilla's firefox icon and mine. mine is similar but looks closer to the old firefox icon and brings back the little arm and gives the fox a cute little smiley face