@briancoords Oh man - as someone who built a SaaS to manage api keys properly in WordPress I can say this has been a big issue for a long time. Options.php gives them up in plain text and doesn’t even need file/db access.
Convincing people of the risk has been an uphill battle.
Buckle up Drupal folks - this has the trappings of a big one. Get yourself up to date and ready to release quickly.
While hosts can/should mitigate at the WAF layer, that's not a backstop to rely on for the long term.
@wpmodder I’ve done quite a bit of sms in my day. Biggest headache is making sure you stay compliant and not getting labeled as spam.
That and watch your costs, they seem cheap then you realize just how many send.
Happy to chat more if you’d like!
@ezsmith397@isvictoriousss@williamsba@harvest To be honest most of the new additions are gated behind paywalls and we’ve never really needed. But simple things like a table that can sort based on the columns isn’t possible for them.
They’re just banking on the fact that it’s critical software and has high switching costs.
@NewYorkerLaura@harvest Our renewal cost went from $2,800 to $24k! We’ve been on the platform for over a decade and are gladly finding other ways to handle it. Either in house via agentic coding our own solution or a competitor who is fairly priced and values their customers.
@alexjvasquez@williamsba@harvest Yeah and in the era of agentic coding and vibe coded startups, putting a nearly 10x increase in costs just invites your new competitors to get all your users.
Just baffling business decisions.
To check if your Google Workspace has been compromised by the same tool that compromised Vercel:
1. Go to https://t.co/TpuIOW5Fwg
- This is Google Admin Console > Security > Access and Data Control > API Controls > Manage app access > Accessed Apps
2. Filter by ID = https://t.co/uqJnCqp5Ah
- This is the ID of the compromised OAuth app
If you see an app after filtering, you have potentially been compromised
@CoenJacobs Later that week at the after party I saw the same people walking, laughing and chatting with Matt the whole night.
The culture of fear was very evident.
@CoenJacobs I went to WordCamp US in Philly, during elevator-gate. I asked folks what was going on.
Multiple people said things like “you can make money in WordPress as long as your name is Matt” and “don’t get in the king’s way” while intentionally hiding their badges to stay anonymous.
@CasJam What I'm working towards is essentially a GitHub repo that gets added to each project as a submodule (or to your local for Cowork etc.) and then updates are just a git push/pull and the bundled tooling syncs Claude.md file, skills etc..
@aaronfeledy The best was Blockbuster’s Mail offering, get 3 in the mail, then return them to the store for 3 more while the others shipped to you.
I literally watched all of the new release section from ‘06-‘08
Kudos to @AnthropicAI for doing the right thing and standing up for the responsible and ethical use of AI.
Not allowing these models to be used to make life and death decisions, subvert democracy, and trample on our constitutional rights is honorable.
This is huge for anyone selling AI services to businesses.
What Cowork + plugins unlocks:
• Custom agent setups per department (sales, marketing, ops)
• Integrations with existing company tools
• Team-specific workflows that actually get adopted
• A reason for enterprises to pay for implementation help
The companies announcing these features aren't building the implementations.
That's your job now.
Gotta love buying a ton of Super Bowl gear for the family within minutes after the @Seahawks won the NFC Championship, only for @Fanatics to not deliver them before the game even though it was billed as "guaranteed delivery".
Their monopoly over sports gear needs to end.
@clifgriffin@autodesk has a free tool version of Fusion for non commercial use that’s great, I’ve gotten the hang of it now and feel pretty comfortable building with it:
https://t.co/clRoUIab1A