cesasol
4.5K posts

cesasol
@Cesasol
Web sorcerer | Esposo y padre de gatitos


For a long time #WordPress has pushed auto-updates, but that needs to change. What used to be the secure thing to do has now become the vulnerability. Based on recent supply chain attacks (NX Console specifically), things like signing & verification means nothing if the developers git SSH keys were compromised. Are there any other changes that can the #WordPress community and wordpress.org specifically do to mitigate these attacks in our space? github.blog/security/inves…

🚨 The "𝙼𝚎𝚐𝚊𝚕𝚘𝚍𝚘𝚗" Campaign is live... 𝟻,𝟽𝟷𝟾 malicious commits to 𝟻,𝟻𝟼𝟷 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected 𝙶𝚒𝚝𝙷𝚞𝚋 𝙰𝚌𝚝𝚒𝚘𝚗𝚜 workflows containing 𝚋𝚊𝚜𝚎𝟼𝟺-𝚎𝚗𝚌𝚘𝚍𝚎𝚍 bash payloads that exfiltrate: - CI secrets, - cloud credentials - SSH keys - OIDC tokens - source code secrets Check your repo / Technical details: safedep.io/megalodon-mass…




To prevent "programmatic use", Claude Code may now request webcam access to assure user is present when prompting

Liquid Glass on Linux🐧🐧🐧



If Bitwarden actually does a rug pull I’m pivoting to the most neckbeardy, FOSS-purist replacement I can find







