"Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of line that will exhaust us to death instead of making us understand your claim."
"Please present your case briefly and to the point. Do not use an AI to help you blab hundreds of line that will exhaust us to death instead of making us understand your claim."
aws.amazon.com/blogs/securi...
aws.amazon.com/blogs/securi...
Each vendor doesn't get their own CVE that corresponds to their security bulletin.
CVE-2025-66478 is REJECTED as duplicate of CVE-2025-55182
www.cve.org/CVERecord?id...
Each vendor doesn't get their own CVE that corresponds to their security bulletin.
CVE-2025-66478 is REJECTED as duplicate of CVE-2025-55182
www.cve.org/CVERecord?id...
www.liquibase.com/blog/liquiba...
www.liquibase.com/blog/liquiba...
It’s not well known outside of security research circles how often GitHub tokens leak.
Good news: No one at AWS (human or AI) merged in a dodgy PR, because...
Bad news: It was an exciting new exploited vulnerability in CodeBuild.
It’s not well known outside of security research circles how often GitHub tokens leak.
"Today, Valkey is maintained by a neutral foundation, ensuring no one company can take it away from open source."
Linux Foundation doesn't maintain Valkey. thenewstack.io/open-source-...
"Today, Valkey is maintained by a neutral foundation, ensuring no one company can take it away from open source."
Linux Foundation doesn't maintain Valkey. thenewstack.io/open-source-...
1) AI can help us build better products through rapid prototyping
2) Devs can declare their app's requirements to get better results from AI, close to production-grade code
1) AI can help us build better products through rapid prototyping
2) Devs can declare their app's requirements to get better results from AI, close to production-grade code
https://daniel.haxx.se/blog/2025/07/11/cybersecurity-risk-assessment-request/
#curl #cra
Unfortunately The Rules don't prohibit allocating a CVE for an identified weakness that was never in a released Product...
www.cve.org/resourcessup....
Unfortunately The Rules don't prohibit allocating a CVE for an identified weakness that was never in a released Product...
www.cve.org/resourcessup....
It's not *just* been Project Zero sending vulnerability disclosures to the maintainer.
gitlab.gnome.org/GNOME/libxml...
It's not *just* been Project Zero sending vulnerability disclosures to the maintainer.
gitlab.gnome.org/GNOME/libxml...
It's infrastructure that we generally take for granted in developed industrialized nations.
It's infrastructure that we generally take for granted in developed industrialized nations.
⬇️
www.kubernetes.dev/blog/2025/06...
⬇️
A zombie CVE from a CNA long dead, a CVSSv3 base score of 9.8 in the NVD, and a weakness that is intrinsic in the language ecosystem (do not deserialize Java from untrusted sources, people!!!).
github.com/spring-proje...
A zombie CVE from a CNA long dead, a CVSSv3 base score of 9.8 in the NVD, and a weakness that is intrinsic in the language ecosystem (do not deserialize Java from untrusted sources, people!!!).
github.com/spring-proje...
the membership.
i had a call with a friend who is executive director of another 501(c)3 and he drew me this picture for his org. i think it's a helpful reminder that the foundation serves the project.
that's the whole reason we're here.