Senior Data Analyst II, Product at MongoDB

MongoDB is hiring Senior Data Analyst II, Product

📝 New blog post: SUDONE をつくった — バーコードで「買う前にネット価格チェック」

店頭で商品のバーコードを読むだけで、楽天・Yahoo!ショッピング・Amazon のネット最安値が約1秒で分かる。SUDONE をつくった理由と、その裏側のアーキテクチャと苦労。

https://blog.arda.tr/blog/2026-06-20-introducing-sudone-barcode-price-check

#dev #go #gcp #japan #product

SUDONE をつくった — バーコードで「買う前にネット価格チェック」 - Coze

店頭で JAN バーコードをスキャンすると、楽天・Yahoo!ショッピング・Amazon のネット価格を即座に比較できるアプリ SUDONE。仕組みと、Go + GCP のアーキテクチャ、静的 IP allowlist や JAN マッチングの苦労まで。日本語と English の両方で。

Coze — blog.arda.tr
Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed

EXCLUSIVE 'Working as intended' for the win … again

theregister
Senior Software Engineer - Application Traffic team at Databricks

Databricks is hiring Senior Software Engineer - Application Traffic team

Google Cloud is such a pain in the ass.

Things encountered today:
* I have an API key, I'm 98% sure it belongs to my organisation, there is no way to figure out where it came from in the UI because there's no unified view of stuff like this I can find.
* No, pathetic user with the "owner" role, you do not have permissions to access API keys via the CLI / SDK. Ok, but what if I impersonate this service account? Well, in that case, go right on ahead.
* You are not permitted to do this, you need to enable billing on this nonexistent project. Actual problem: incorrect permissions
* Fix permissions on a user, run command again, still fails, triple check permissions, they are correct, run command a third time, works.

This wasted half an hour of my morning.

That said the ability to see exactly what permission changes you're making to a user is pretty damn cool, even though you're changing permissions by assigning GCP managed roles which can change at any time.

AWS is deceptively simple cloud stuff that occasionally doesn't work for annoying and complicated reasons, but the threads to pull on are limited. Google Cloud is engineering cloud for engineers who understand Google Cloud and finding a solution when something simple and obvious doesn't work can be very very involved.

#gcp #googlecloud #tech #it

📰 Pickle in the Middle: Critical RCE Flaw in Google Vertex AI Enables ML Model Hijacking

⚠️ Unit 42 discovers critical RCE flaw in Google's Vertex AI SDK! Attackers can hijack ML models via 'bucket squatting,' leading to cross-tenant compromise. Patch `google-cloud-aiplatform` to v1.148.0+ now! #VertexAI #GCP #CyberSecurity #RCE

🌐 cyber[.]netsecops[.]io

🔗 https://cyber.netsecops.io/articles/pickle-in-the-middle-hijacking-vertex-ai-model-uploads-for-cross-tenant-rce/…

Senior Backend Engineer (SaaS, Data & AI) at Kaseya

Kaseya is hiring Senior Backend Engineer (SaaS, Data & AI)

Principal Security Engineer, Security at Circle

Circle is hiring Principal Security Engineer, Security

Senior Security Engineer II at Contentstack

Contentstack is hiring Senior Security Engineer II

Senior Software Engineer, Server Security at MongoDB

MongoDB is hiring Senior Software Engineer, Server Security