112 Followers
296 Following
564 Posts

Today in InfoSec Job Security News:

I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically.

So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month.

https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc

As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.

Build software better, together

GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.

GitHub

A - DNS Record
AA - Battery
AAA - Battery
AAAA - DNS Record

edit: originally by @kevin , inadvertently copied https://mastodon.km6g.us/@kevin/113724524588964200

Kevin P. Fleming (@[email protected])

A - DNS record AA - battery AAA - battery AAAA - DNS record #DNS #Battery #Confusion

KM6G Mastodon
By Dutch cartoonist Tjeerd Royaards

Brits should read this ⬇️ exchange between Epstein and Thiel.

Epstein explicitly mentioned Brexit as a successful step to destabilize societies in order to create profit opportunities.

This email between #Epstein and JD Vance’s tech oligarch benefactor fascist Peter Thiel where they plan to “collapse” society to create investment opportunities for themselves.

Epstein and Thiel also met with the UN ambassador to Russia together. Russia carried out successful hybrid warfare operations against the United Kingdom (Brexit) and the United States (Trump-for-President) in 2016.

#EpsteinFiles #uk #England #Britain #europe #europeanunion #eu #usa #news

"The most corrupt president The United States have ever seen."

UK Member of Parliament Ed Davey does not mince words when characterizing Trump after his move to take Greenland.

Thanks for the tip @hadon.

Y’all, please continue to boost good posts you see. I’ve realized that almost all of my discovery of new (to me) accounts on Mastodon comes from when you boost something, I like it, and click through to the original poster to check them out and end up following them.

SVG icons have been "solved" myriad ways, but I find them all lacking.

Inline SVGs? Bloated DOM.
<img> tags? Can't change colors.
Icon fonts? Blurry at certain sizes, a11y issues.
CSS background-image? Still can't change colors.

But, today there's actually a perfect solution...

"Let us be the repository of your passkeys" and "We may terminate your account at any time and permanently refuse to communicate with you" ... seems like a bad combination?