Links
Add
CodeQLEAKED – Public Secrets Exposure Leads to Supply Chain Attack on GitHub CodeQL
https://www.praetorian.com/blog/codeqleaked-public-secrets-exposure-leads-to-supply-chain-attack-on-github-codeql/
An exposed GitHub token could have been used to launch a supply chain attack on GitHub CodeQL, resulting in source code exposure and repository tampering of CodeQL users.
The Worm That No Computer Scientist Can Crack | WIRED
https://www.wired.com/story/openworm-worm-simulator-biology-code/
One of the simplest, most over-studied organisms in the world is the C. elegans nematode. For 13 years, a project called OpenWorm has tried—and utterly failed—to simulate it.
Added 1 month ago
Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog
https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities
Added 1 month ago
https://cybernews.com/security/troy-hunt-falls-victim-to-phishing-attack/
https://cybernews.com/security/troy-hunt-falls-victim-to-phishing-attack/
Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH
https://blog.cloudflare.com/open-sourcing-openpubkey-ssh-opkssh-integrating-single-sign-on-with-ssh/
OPKSSH (OpenPubkey SSH) is now open-sourced as part of the OpenPubkey project. This enables users and organizations to configure SSH to work with single sign-on technologies like OpenID Connect, removing the need to manually manage & configure SSH keys without adding a trusted party other than your IdP.
Added 1 month ago
Added 1 month ago
IssueOps: Automate CI/CD (and more!) with GitHub Issues and Actions - The GitHub Blog
https://github.blog/engineering/issueops-automate-ci-cd-and-more-with-github-issues-and-actions/
A look into building IssueOps workflows on GitHub to do everything from CI/CD to handling approvals and more.
Added 1 month ago
reviewdog/action-setup
https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup
Added 1 month ago
5 reasons ZeroTier is the best Tailscale alternative for your home lab
https://www.xda-developers.com/why-zerotier-is-the-best-tailscale-alternative-for-your-home-lab/
There's a million ways to connect to your home lab, but some options are better for your needs.
Added 1 month ago
Google says its new Linux Terminal feature isn't a replacement for Android's desktop mode
https://www.androidauthority.com/android-linux-terminal-purpose-3535765/
A Google employee has finally revealed why the Linux Terminal app was added to Android, as well as some info on the future of Linux apps.
GitHub Actions now supports a digest for validating your artifacts at runtime - GitHub Changelog
https://github.blog/changelog/2025-03-18-github-actions-now-supports-a-digest-for-validating-your-artifacts-at-runtime/
Developers using upload-artifact and download-artifact in their Actions workflows can now ensure the integrity of their artifacts with the new SHA256 digest. This feature automatically verifies that the artifact uploaded…
Added 1 month ago
GIMP 3.0 Released - GIMP
https://testing.gimp.org/news/2025/03/16/gimp-3-0-released/
Release notes for GIMP 3.0
Added 1 month ago
Baidu Inc. on X: "We've just unveiled ERNIE 4.5 & X1! 🚀 As a deep-thinking reasoning model with
https://x.com/Baidu_Inc/status/1901089355890036897
giacomo-b/rust-stakeholder
https://github.com/giacomo-b/rust-stakeholder
Generate impressive-looking terminal output to look busy when stakeholders walk by - giacomo-b/rust-stakeholder
Lynx is the oldest web browser still being maintained | Hacker News
https://news.ycombinator.com/item?id=43377829
Added 1 month ago
Harden-Runner detection: tj-actions/changed-files action is compromised - StepSecurity
https://search.app/nz29ggeNi26oEF8q9
Added 1 month ago
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials - The GitHub Blog
https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
Added 1 month ago
🔭 The Einstein AI model
https://thomwolf.io/blog/scientific-ai.html
I shared a controversial take the other day at an event and I decided to write it down in a longer format: I’m afraid AI won't give us a compressed 21st century.
Open Infrastructure Map
https://openinframap.org/#8.3/-27.585/153.024
Open map of the world's electricity, telecoms, oil, and gas infrastructure, using data from OpenStreetMap.
Added 1 month ago
RLAMA | Retrieval-Augmented Local Assistant Model Agent
https://rlama.dev/
Complete AI Platform: RAG Systems & Intelligent Agents for Local AI
Added 1 month ago
Revolt - Find Your Community
https://revolt.chat/
Revolt is the chat app that's truly built with you in mind.
Added 1 month ago
https://edition.cnn.com/science/live-news/moon-landing-blue-ghost-03-02-25/index.html
https://edition.cnn.com/science/live-news/moon-landing-blue-ghost-03-02-25/index.html
A robotic lunar lander built by Texas-based Firefly has successfully landed on the moon, becoming only the second private-sector company ever to complete such a feat.
Added 1 month ago