

Matheus Chimelli
61 posts

@mtschml
a lawyer building SAASs building https://t.co/t5jN4rMxuh







Gemini 3.5 Flash ranks #1 on the APEX-Agents-AA benchmark, outperforming much larger models a whole size above it.


estamos fora do ar o google cloud baniu a conta da railway e derrubou completamente a infraestrutura de todos os clientes deles incluindo nós isso é inacreditável bicho


SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

You should never ever expose a VPS to the entire internet Always firewall it to subnets If you host a website you should only allow port 443 (HTTPS) inbound from Cloudflare's IP range / subnets Port 22 (SSH) only from your Tailscale subnet range That means you create a "tunnel" from Cloudflare and Tailscale (your laptop) to your server's door You still need your SSH key to open the door btw If you don't, ANYONE in the entire world can connect to your VPS and if there's just one security vulnerability and you didn't upgrade your VPS you can get hacked If you do have it firewalled with Tailscale subnet only, it means only if they hack your laptop they could get in via your Tailscale there Another thing is ask OpenClaw or Claude Code to enable unattended upgrades with auto reboot










