1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
Hablemos de CVE-2026-31431 o "Copy Fail" es una vulnerabilidad que afecta TODOS los kernels de Linux desde 2017 en adelante y permite ganar acceso root con una línea de código:
The NAT Gateway on AWS is one of the most costly resources for many teams.
The NAT Gateway allows you to have resources running in a private network (Virtual Private Cloud - VPC) but still having them get access to internet based resources.
One part of how NAT Gateways work on AWS that many don't understand is that calls to AWS services from within a VPC will go over NAT Gateways unless you setup VPC Endpoints to allow a more direct connection to these AWS services from your VPC.
AWS charges a fix price to have NAT Gateways up and running but the big concern is the per GB charges for data passing through it.
This article from Eran Levy discusses how they were seeing huge NAT Gateway costs and used tools like VPC Flow Logs and Athena to query those to narrow down the problems and fix their misconfiguration.
Teams running in the cloud need to have people with knowledge of how VPC networking and AWS pricing works or they will likely end up paying a lot of unneeded $$$s to AWS.
CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed. We refer customers to the support portal for the latest updates and will continue to provide complete and continuous updates on our website. We further recommend organizations ensure they’re communicating with CrowdStrike representatives through official channels. Our team is fully mobilized to ensure the security and stability of CrowdStrike customers.
@openbank_es funcionaba de maravilla, todo desde la app /web, ahora desde este año experimento PERDIDAD DE SALDO (dinero) en la tarjeta #ecard, cargas que no se reflejan, teniendo que llamar a sus oficinas para pedir que se revisen los movimiento y que el dinero aparezca. Fatal!!
HashiCorp #Terraform 1.9 is now generally available. Discover the latest upgrades including advanced input variable validations and a new string templating function. https://t.co/h9dZRiB05S
Today, we released Quarkus 3.12. It comes with a centralized TLS registry, load shedding and Podman extensions and the ability to use the native image agent easily. For Kotlin enthusiasts, we also upgraded our Kotlin support to Kotlin 2.0. https://t.co/l4hMadQqrE
There are also NO large meetings.
Anyone can walk out of a meeting if they're not contributing or don't feel they need to be there.
According to Elon, small teams make quick and independent decisions.
Look at the email he wrote to employees 👇
Google Cloud accidentally deleted a company's entire cloud environment (Unisuper, an investment company, which manages $80B). The company had backups in another region, but GCP deleted those too. Luckily, they had yet more backups on another provider.
https://t.co/v5WFxqUtaB
Un hacker traza un meticuloso plan por 2 años para colar un acceso a casi todos los sistemas Linux del mundo.
Su plan se frustra porque un developer en algún lugar del mundo nota que su acceso ssh era 0,5 segundos más lento de lo habitual.
El poder del TOC 🤣
A great #KubeConEU in Paris! We were so excited to see over 50 community event organizers from KCDs to European community groups across the globe. And we are proud of the representation on the keynote stage and the project pavilion.👏🏻💪🏾🤟
#BetterTogether at @KubeCon_ 🌍📷💛
AWS to Shut down Aurora Serverless v1, Their Sole Relational Database with Scaling Capacity to Zero
At least they have now the new #RDSAPIv2 that was something missing a long time ago since Aurora Serverless V2 was released.
https://t.co/Yn0xoTVzZo
AWS announced earlier this year they would start charging for IPv4 addresses you use in your accounts starting in about 3 months from now.
This change will likely impact almost everyone using AWS.
@suhailist talks about why and if you can do anything. https://t.co/ag1wHUGC0y
Brecha de LinkedIn con 35 Millones de registros y 2,7 GB de datos personales publicada en BreachForums totalmente en abierto.
#hacking#ciberseguridad#infosec
🇪🇸Un error de Hacienda deja al descubierto datos de cuentas bancarias de contribuyentes
🔽Solo se revelará el alcance total del incidente después de que la Agencia de Protección de Datos complete su investigación
https://t.co/BLCkgGRuEb