[Sidrops] first route leak prevented by ASPA
Getting started using Zapier's Chrome Extension
Things to do and not to do during a wave of tech layoffs | Christian Heilmann
What is Gateway API for Kubernetes? Find out in ten minutes!
The evolution of Kubernetes service networking is here.
Join us on this quick tour of what Gateway API is all about!
Timecodes:
0:00 Introduction
3:50 Installation
10:10 Conclusion
Move over, npm: Now VS Code extensions can’t be trusted
It’s super easy to spoof Visual Studio Code extensions. And it’s incredibly hard to detect. In this week’s Secure Software Blogwatch, we run and hide.
openebs/zfs-localpv: CSI Driver for dynamic provisioning of Persistent Local Volumes for Kubernetes using ZFS.
Perception matters — make people feel heard - Duck Alignment Academy
Traefik Proxy now offers Tailscale as certificate resolver
Traefik, the popular load balancing and reverse proxy tool, has added support for Tailscale as a certificate resolver in Traefik Proxy 3.0 beta, the latest release of its forward proxy offering. Today, one of the engineers behind this integration has published a fun deep dive into how it works and how they’re using Tailscale to help with testing at Traefik.
Windows Package Manager now supports aliases (so you can use Linux commands) - Liliputing
Windows Package Manager now supports aliases (so you can use Linux commands)
Sliver C2 Leveraged by Many Threat Actors
Threat Research: Sliver C2 gets more and more traction from Threat Actors, often seen as an alternative from Cobalt Striker.
Ivory for Mastodon Review: Tapbots Reborn
There’s an intangible, permeating quality about Tapbots apps that trascends features and specs: craftsmanship. With Ivory, launching today on the App Store for iPhone and iPad, you can instantly appreciate that level of care and refinement that the Texas-based duo is well known for after more than a decade on the App Store. But there’s
Jack Henry Incorporates BubbleUp and Honeycomb’s New Service Map to Quickly Debug Issues and Get Ahead of Customer Latency | Honeycomb
Join Zach McCoy from Jack Henry as he explains how the company is leveraging Service Map and BubbleUp to surface issues quickly and easily.
Y’all, SBOMs don’t give you a full picture. @OmniBOR is looking to address this and we could use your help! | OpenSSF Aimed to Stem Open Source Security Problems in 2022
In 2022, the Open Source Software Foundation (OpenSSF) set its sights on fixing security problems with the open software supply chain. including joining forces with companies including Apache, Google, Apple, and AWS, and meeting at the White House with the U.S. government's executive branch.
How a CEO Can Create Psychological Safety in the Room
As the CEO, your mere presence in a room dictates the power dynamic. The paradox of being a CEO is that your job is to encourage useful ideas, and yet your very presence can work against that objective. So can your desire to indulge in the dark side of charisma to seek admiration. Ironically, you must overcome the interpersonal liability of your role in order to perform it. How, then, can you create high levels of psychological safety to promote the unencumbered exchange of ideas and unedited circulation of feedback? The author, who has worked with hundreds of CEOs over the past 25 years, offers 10 practical ways to make that happen.
Microsoft Agrees To Multibillion-Dollar Deal With OpenAI
Microsoft confirmed it has agreed to a “multiyear, multibillion-dollar investment” into OpenAI, the startup behind ChatGPT and DALL-E.
InfoSec Handlers Diary Blog - SANS Internet Storm Center
Who's Resolving This Domain?, Author: Xavier Mertens
NSA IPv6 Security Guidance
Speaker Rider
Chris Short is happy to speak at your event but, there are some things I need before I can commit.
Week Ending January 22, 2023
Developer News
K8s ASA: The Storage Interface
Like most API servers, a, if not the, primary function of the Kubernetes API Server is to ingest data, store it, then return it when requested. Today we are going to be focusing on how the API Server stores data.
Table of Contents:
The apiserver Module (👈 “I want all the details.”) The storage Package Our Good Friend etcd The API Server and etcd Calling storage.Interface Directly (👈 “Can we skip the background info?
Samsung 990 Pro SSDs Report Rapid Health Degradation
Some drives lost 10% of health in just a few weeks.
GitHub Container Registry private repos sometimes… weren’t
GitHub Container Registry (GHCR) had an information leak bug, where names of private repos were exposed. Here's the background on how it was reported and fixed. Everything you need to know about securing the software supply chain.
1st small modular nuclear reactor certified for use in US
The U.S. Nuclear Regulatory Commission has certified the design for what will be the United States' first small modular nuclear reactor. The rule that certifies the design was published Thursday in the Federal Register.
Beyond Git: The other version control systems developers use
Our developer survey found 93% of developers use Git. But what are the other 7% using?
CNET's AI Journalist Appears to Have Committed Extensive Plagiarism
CNET's AI-generated articles appear to show deep structural similarities, amounting to plagiarism, with previously published work elsewhere.
Attacks on U.S. Jews and gays accelerate as hate speech grows on Twitter
Former employees and online researchers say an increase in physical attacks in the United States tracks with spikes in some categories of hate speech on Twitter, notably antisemitic and anti-gay slurs and rhetoric.
Google Parent Alphabet to Cut 12,000 Jobs
The layoffs amount to about 6 percent of the global work force at the company, the latest tech giant to make cuts after a pandemic hiring spree.
Backdoor into FortiOS: Chinese Threat Actors Utilize 0-Day
Follow us on Twitter @HackRead - Facebook @ /HackRead
Spotify to trim 6% of workforce, content head to depart
Music streaming firm Spotify plans to cut 6% of its workforce, the company said on Monday, a move that will add to a glut of layoffs in the technology sector.
A hack at ODIN Intelligence exposes a huge trove of police raid files
The breach exposes the police tech firm's own systems but also confidential law enforcement data uploaded by ODIN's police customers.